Technology content trusted by users in North America and around the world.
4,951 Articles | 29,850 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

USA EditionYou are located: Home > All News > Hacking & Security News > PDF file format found to be a vector for attack

PDF file format found to be a vector for attack

By: (more) | Hacking & Security News | Posted: Apr 6, 2010 2:10 am

We have all heard about how Adobe's Acrobat Reader and Flash browser plug-ins are vulnerable to exploits. But did you know that the actual file format specification for all PDFs is also a vector for attack?

 

The ISO standard for PDFs (ISO PDF 32000-1:2008) details the functionality that is present in the file format and outlines the launch command. This launch specification can allow malicious coders to imbed scripted commands that can infect even a clean PDF. There is no need to exploit javascript or another zero-day exploit. As the code executes in the PDF the user will be presented with a dialog box asking if he or she wants to run the code. A clever attacker can design the dialog to entice the user into thinking they need to click this. This is a proven technique used by many "scare-ware" vendors. They fool the user into thinking they are infected with a virus and by clicking on a button it will clean it off for them.
Both Adobe and Foxit are working ways to correct the issue or at least provide additional user warnings about the danger of opening unknown PDFs.

 

 


SOURCE #1

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: SuperSpeed RamDisk Plus 11 Software Review
  • Upcoming Content: HP Envy TouchSmart 4 Touchscreen Ultrabook Laptop Review
  • Upcoming Content: MSI Radeon HD 7790 1GB OC Overclocked Video Card Review
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: Kingston DT Workspace 64GB 'Windows To Go' USB 3.0 Flash Drive Review
  • Upcoming Content: Lexar Professional 128GB Compact Flash Memory Card Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review

Hacking & Security News Posts

View More Hacking & Security News Posts

TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases