Adobe .pdf back doors
p2pnet.net News:- UK security researcher David Kierznowski says legitimate features in Adobe PDF files can be used to open back doors for hack attacks.
Kierznowski, a penetration testing expert, has released proof-of-concept code and rigged PDF files, “to demonstrate how the Adobe Reader program could be used to launch attacks without any user action,” says eWEEK.
But, “I do not really consider these attacks as vulnerabilities within Adobe,” the story has him saying. “It is more exploiting features supported by the product that were never designed for this,” Kierznowski stated.
“The first back door (PDF), which eWEEK confirmed on a fully patched version of Adobe Reader, involves adding a malicious link to a PDF file,” says the story. “Once the document is opened, the target’s browser is automatically launched and loads the embedded link”and, “At this point, it is obvious that any malicious code [can] be launched,” Kierznowski said.
Also See:
eWEEK – Hacker Discovers Adobe PDF Back Doors, September 15, 2006
p2pnet newsfeeds for your site.
rss feed: http://p2pnet.net/p2p.rss
Mobile – http://p2pnet.net/index-wml.php





September 16th, 2006 at 8:23 pm
simple, just don’t click on any links in a downloaded PDF.
it’s not like any of the PDFs out there even have working links anyways.
still it’s pretty unsettling that people are using ebooks, to exploit others. I bet hollywood is using this technology already or has been for sometime. either way once agian common sense leaves you from being harmed.
September 17th, 2006 at 10:15 am
Even though there is no real need for such a feature in acrobat, i think that PEBKAC’s are the real problem here.
I mean even if this kind of feature had been exploited by malware-for-profit authors and sent out in every spam email for the next millenium, if it wasn’t for PEBKAC’s it would never be an issue. If PEBKAC’s didn’t exist, i don’t believe spam would exist either.
We need to solve PEBKAC’s somehow. Permanently.
Note: For those who don’t know what a PEBKAC is, it’s an acronym. Try looking it up.