Date: April 2nd, 2010

Hacker Punches Through Adobe PDF Reader Without a Vulnerability

A security researcher has managed to create a proof-of-concept PDF file that executes an embedded executable without exploiting any security vulnerabilities.

The PDF hack, when combined with clever social engineering techniques, could potentially allow code execution attacks if a user simply opens a rigged PDF file.

Here’s the skinny from researcher Didier Stevens:

I use a launch action triggered by the opening of my PoC PDF. With Adobe Reader, the user gets a warning asking for approval to launch the action, but I can (partially) control the message displayed by the dialog. Foxit Reader displays no warning at all, the action gets executed without user interaction.

Although PDF viewers like Adobe Reader and Foxit Reader doesn’t allow embedded executables (like binaries and scripts) to be extracted and executed, Stevens discovered another way to launch a command (/Launch /Action), and ultimately run an executable he embedded using a special technique.

Stevens said Adobe’s PDF Reader will block the file from automatically opening but he warned that an attacker could use social engineering tricks to get users to allow the file to be opened.

With Foxit Reader, there is no warning whatsoever:

Stevens has not released the proof-of-concept file. The issue has been reported to Adobe’s security response team.

With Adobe Reader, the only thing preventing execution is a warning. Disabling JavaScript will not prevent this (I don’t use JavaScript in my PoC PDF), and patching Adobe Reader isn’t possible (I’m not exploiting a vulnerability, just being creative with the PDF language specs).

Stevens tested his research on Adobe Reader 9.3.1 (Windows XP SP3 and Windows 7).

Source: ZDNet

Related posts:

  1. World Cup Fans Beware of Infected PDF Files
  2. Hacker Exploits Previously Unknown FireFox Flaw to Take Control of Windows 7 PC
  3. IE 8 Successfully Exploited to Attack Fully Patched Windows 7 PC
  4. Wholefoods Facebook Scam Steals Your Info

Leave a Reply

Latest Releases

Top 10 Spy Gadgets You Can Own Right Now

Spies are everywhere these days, from the 10 Russian agents nabbed recently here ...

Etsy a Destination for Home Crafters to Market their Wares

Today we take a peek inside the offices of Etsy, the company behind ...

Want to Go Into Space? Comming Soon to a Launchpad Near You…

This is Boeing's new Crew Space Transportation-100 spacecraft. It is similar to Apollo's ...