main
Report a problem

PDF security risk greater than originally thought

Marshalus   on 05 January 2007 - 15:47 · 6 comments & 3916 views

Advertisement (Why?)
A recently discovered security weakness in the widely used Acrobat Reader software could put Net users at more risk than previously thought, experts warned Thursday.

Initially, security professionals thought that the problem was restricted and exposed only Web-related data or could support phishing scams. Now it has been discovered that miscreants could exploit the problem to access all information on a victim's hard disk drive, said Web security specialists at WhiteHat Security and SPI Dynamics.

Key to increased access is where hostile links point. When the issue was first discovered, experts warned of links with malicious JavaScript to PDF files hosted on Web sites. While risky, this actually limits the attacker's access to a PC. It has now been discovered that those limits can be removed by directing a malicious link to a PDF file on a victim's PC.

"This means any JavaScript can access the user's local machine," Billy Hoffman, lead engineer at SPI Dynamics, said in an e-mailed statement. "Depending on the browser, this means the JavaScript can read the user's files, delete them, execute programs, send the contents to the attacker, et cetera. This is much worse than an attack in the remote zone."

For an attack to work, a malicious link has to point to an existing PDF file on the Web or on the target system. PDFs are abundant on the Net and finding one on a local system also isn't hard, a sample PDF file comes with Acrobat Reader and is installed in a predictable location on PCs, Grossman said.

News source: CNET

Post a comment · Send to friend Comments · There are 6 additional comments
#1 Slimy on 05 Jan 2007 - 16:53
There is no such thing as Acrobat Reader, it was renamed a while ago.
Like I said before, Adobe Reader 8 is unaffected so this really isn't a big deal.
(3 replies) #2 IntelliMoo on 05 Jan 2007 - 17:09
Foxit Reader! Period.
#2.1 guylaroche on 05 Jan 2007 - 17:26
Quote - (IntelliMoo said @ #2)
Foxit Reader! Period.
+1
#2.2 Aero Ultimate on 06 Jan 2007 - 02:14
+2

Who's stupid enough to use that bloated Adobe crap gets what (s)he deserves
#2.3 RealFduch on 06 Jan 2007 - 10:13
Quote - (Aero Ultimate said @ #2.2)
+2

Who's stupid enough to use that bloated Adobe crap gets what (s)he deserves


I think that (MS haters ++ Apple fanboys) are. They use closed PDF format because it's not from MS. And they use Adobe products because Adobe is close to Apple.
#3 Arcticflare on 05 Jan 2007 - 22:34
So basically all this means is that people who never do updates will be subject to holes in their crusty software. So it's not really news per say...

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)