Page 1 of 1

Adobe .pdf back doors

Posted: Sat Sep 16, 2006 4:40 pm
by p2p-sharing-rules
p2pnet.net News:- UK security researcher David Kierznowski says legitimate features in Adobe PDF files can be used to open back doors for hack attacks.

Kierznowski, a penetration testing expert, has released proof-of-concept code and rigged PDF files, "to demonstrate how the Adobe Reader program could be used to launch attacks without any user action," says eWEEK.

But, "I do not really consider these attacks as vulnerabilities within Adobe," the story has him saying. "It is more exploiting features supported by the product that were never designed for this," Kierznowski stated.

"The first back door (PDF), which eWEEK confirmed on a fully patched version of Adobe Reader, involves adding a malicious link to a PDF file," says the story. "Once the document is opened, the target's browser is automatically launched and loads the embedded link"and, "At this point, it is obvious that any malicious code [can] be launched," Kierznowski said.
p2pnet