Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow PDF exploited without vulnerability
EH-Net
May 25, 2013, 11:31:25 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: PDF exploited without vulnerability  (Read 6013 times)
0 Members and 1 Guest are viewing this topic.
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« on: March 31, 2010, 05:03:08 AM »

A researcher (from Belgium! Wink ) has found a way to exploit pdf files, without using a vulnerability. He created a pdf file with an embedded executable, which will start when the pdf file is opened.

http://blogs.zdnet.com/security/?p=5929

Pretty cool it seems, as far as my knowledge about the subject goes Smiley

Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #1 on: March 31, 2010, 07:16:57 AM »

That's a very cool exploit.   I can't wait to see to the PDF language behind it.
Logged

~~~~~~~~~~~~~~
Ketchup
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #2 on: March 31, 2010, 07:19:53 AM »

Nice find! i like the part that Foxit Reader doesnt even give a warning! (it just executes the script without ant notification) A lot of people are switching to Foxit, so this proves that alternatives arent always better!
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Synquell
Full Member
***
Offline Offline

Posts: 169



View Profile
« Reply #3 on: March 31, 2010, 07:34:01 AM »

Idd Smiley Now let's hope that Adobe fixes it asap (for once)
Logged

Twitter: https://twitter.com/dietervds
Blog: https://synquell.wordpress.com (not much there yet)

The beginning of knowledge is the discovery of something we do not understand.
j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #4 on: March 31, 2010, 08:19:23 AM »

just read that foxit will fix the problem first thing next week:

http://forums.foxitsoftware.com/showthread.php?p=41323

lets see how Adobe will do...
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
UNIX
Hero Member
*****
Offline Offline

Posts: 1235


View Profile
« Reply #5 on: April 01, 2010, 12:48:13 AM »

Interesting, looking forward to more details on this.
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #6 on: April 01, 2010, 12:54:53 AM »

So, metaphish uses this functionality only with javascript. I believe Dave Kennedy will be implementing into SET (the Social Engineering Toolkit) soon =)

So many ways to trick the user =(
Logged

j0rDy
Hero Member
*****
Offline Offline

Posts: 590


View Profile
« Reply #7 on: April 01, 2010, 02:25:12 AM »

here is the link to his blog:

http://blog.didierstevens.com/2010/03/29/escape-from-pdf/

and here is a direct link to a zip file with the malicious file inside. dont worry, it will only spawn a command prompt. maybe you can do some reverse engineering on it?

http://didierstevens.com/files/data/launch-action-cmd.zip

Don: Can i post this or is it out of bounds?
Logged

ISC2 Associate, CEH, ECSA, OSCP, OSWP

earning my stripes appears to be a road i must travel alone...with a little help of EH.net
n1p
Jr. Member
**
Offline Offline

Posts: 89


View Profile WWW
« Reply #8 on: April 01, 2010, 05:52:10 AM »


and here is a direct link to a zip file with the malicious file inside. dont worry, it will only spawn a command prompt. maybe you can do some reverse engineering on it?

Guys, since I had some spare time Smiley, just a small write-up on this to demonstrate how it occurs in the PDF. Thought you all might be interested.

http://www.isolatedthreat.com/?p=214

As usual comments welcome.

n1p
« Last Edit: April 01, 2010, 05:53:55 AM by n1p » Logged
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #9 on: April 01, 2010, 07:18:55 AM »

The cool thing about this one is that it doesn't rely on JavaScript being enabled in Adobe.   It must be using the built in language. 

Nice write-up btw n1p.
Logged

~~~~~~~~~~~~~~
Ketchup
n1p
Jr. Member
**
Offline Offline

Posts: 89


View Profile WWW
« Reply #10 on: April 01, 2010, 08:02:52 AM »

Yes, it is using the PDF language spec, but not in the way they intended Tongue

Malware uses a variety of techniques to embed in a PDF, so I will be interested to see how he has done it... And how vendors respond
Logged
Jhaddix
Sr. Member
****
Offline Offline

Posts: 317



View Profile WWW
« Reply #11 on: April 01, 2010, 09:22:28 AM »

Testing a /dev/tcp version atm that will send goodness over the wire in *nix =)
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.104 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.