Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Malicious PDF files

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
4,032
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Sep 28, 2009

In this video, security researcher and expert on malicious PDF files Didier Stevens discusses how these files work and offers protection tips.

For more security-related material visit Help Net Security: http://www.net-security.org

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • Yes, I've done tests with this using Adobe and Foxit. You can find it on my blog (sorry, can't post links in comment here).

    Adobe Reader will ask permission for every action (like launching a program for an embedded file, launching your browser, turning on full screen, ...)

    Previous versions of Foxit didn't ask for permission when the browser was launched to vist a website (/AA + /URI), but they fixed this when I reported it.

  • Have you done any work, or seen any exploits which use the OpenAction[1] which can then launch applications[2], do URI actions, or embedded goto actions? It seems that these would be potential attack vectors for sites which do nasty things such as browser exploits, or at a minimum could be used for tracking and information gathering. None of this would require javascript, but I'm not sure if there are other protections in place.

    [1] p74 of PDF 1.7 spec

    [2] p418 of PDF 1.7 spec

  • great video man thanks!

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more