Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 37 guests online
You are here:
Home
Resources
News from the Outside World
PDF exploited without vulnerability
EH-Net
May 25, 2013, 11:31:25 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Resources
>
News from the Outside World
(Moderator:
don
) >
PDF exploited without vulnerability
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: PDF exploited without vulnerability (Read 6013 times)
0 Members and 1 Guest are viewing this topic.
Synquell
Full Member
Offline
Posts: 169
PDF exploited without vulnerability
«
on:
March 31, 2010, 05:03:08 AM »
A researcher (from Belgium!
) has found a way to exploit pdf files, without using a vulnerability. He created a pdf file with an embedded executable, which will start when the pdf file is opened.
http://blogs.zdnet.com/security/?p=5929
Pretty cool it seems, as far as my knowledge about the subject goes
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
Ketchup
Hero Member
Offline
Posts: 1021
Re: PDF exploited without vulnerability
«
Reply #1 on:
March 31, 2010, 07:16:57 AM »
That's a very cool exploit. I can't wait to see to the PDF language behind it.
Logged
~~~~~~~~~~~~~~
Ketchup
j0rDy
Hero Member
Offline
Posts: 590
Re: PDF exploited without vulnerability
«
Reply #2 on:
March 31, 2010, 07:19:53 AM »
Nice find! i like the part that Foxit Reader doesnt even give a warning! (it just executes the script without ant notification) A lot of people are switching to Foxit, so this proves that alternatives arent always better!
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Synquell
Full Member
Offline
Posts: 169
Re: PDF exploited without vulnerability
«
Reply #3 on:
March 31, 2010, 07:34:01 AM »
Idd
Now let's hope that Adobe fixes it asap (for once)
Logged
Twitter:
https://twitter.com/dietervds
Blog:
https://synquell.wordpress.com
(not much there yet)
The beginning of knowledge is the discovery of something we do not understand.
j0rDy
Hero Member
Offline
Posts: 590
Re: PDF exploited without vulnerability
«
Reply #4 on:
March 31, 2010, 08:19:23 AM »
just read that foxit will fix the problem first thing next week:
http://forums.foxitsoftware.com/showthread.php?p=41323
lets see how Adobe will do...
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
UNIX
Hero Member
Offline
Posts: 1235
Re: PDF exploited without vulnerability
«
Reply #5 on:
April 01, 2010, 12:48:13 AM »
Interesting, looking forward to more details on this.
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: PDF exploited without vulnerability
«
Reply #6 on:
April 01, 2010, 12:54:53 AM »
So, metaphish uses this functionality only with javascript. I believe Dave Kennedy will be implementing into SET (the Social Engineering Toolkit) soon =)
So many ways to trick the user =(
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
j0rDy
Hero Member
Offline
Posts: 590
Re: PDF exploited without vulnerability
«
Reply #7 on:
April 01, 2010, 02:25:12 AM »
here is the link to his blog:
http://blog.didierstevens.com/2010/03/29/escape-from-pdf/
and here is a direct link to a zip file with the malicious file inside. dont worry, it will only spawn a command prompt. maybe you can do some reverse engineering on it?
http://didierstevens.com/files/data/launch-action-cmd.zip
Don: Can i post this or is it out of bounds?
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
n1p
Jr. Member
Offline
Posts: 89
Re: PDF exploited without vulnerability
«
Reply #8 on:
April 01, 2010, 05:52:10 AM »
Quote from: j0rDy on April 01, 2010, 02:25:12 AM
and here is a direct link to a zip file with the malicious file inside. dont worry, it will only spawn a command prompt. maybe you can do some reverse engineering on it?
Guys, since I had some spare time
, just a small write-up on this to demonstrate how it occurs in the PDF. Thought you all might be interested.
http://www.isolatedthreat.com/?p=214
As usual comments welcome.
n1p
«
Last Edit: April 01, 2010, 05:53:55 AM by n1p
»
Logged
Ketchup
Hero Member
Offline
Posts: 1021
Re: PDF exploited without vulnerability
«
Reply #9 on:
April 01, 2010, 07:18:55 AM »
The cool thing about this one is that it doesn't rely on JavaScript being enabled in Adobe. It must be using the built in language.
Nice write-up btw n1p.
Logged
~~~~~~~~~~~~~~
Ketchup
n1p
Jr. Member
Offline
Posts: 89
Re: PDF exploited without vulnerability
«
Reply #10 on:
April 01, 2010, 08:02:52 AM »
Yes, it is using the PDF language spec, but not in the way they intended
Malware uses a variety of techniques to embed in a PDF, so I will be interested to see how he has done it... And how vendors respond
Logged
Jhaddix
Sr. Member
Offline
Posts: 317
Re: PDF exploited without vulnerability
«
Reply #11 on:
April 01, 2010, 09:22:28 AM »
Testing a /dev/tcp version atm that will send goodness over the wire in *nix =)
Logged
GSEC, GPEN, GWAPT, ECPPT, WAHHlive, LSOAdvancedPenTester
http://www.securityaegis.com
http://www.pentesterscripting.com
http://code.google.com/p/pentest-bookmarks/
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(30) by
don
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.