5 ms·
These blogs are not very good. Here is the PDF about this vuln. https://www.welivesecurity.com/wp-content/uploads/2018/09/ESET-LoJax.pdf https://www.welivesecu
by romed 8y ago
These blogs are not very good. Here is the PDF about this vuln.
https://www.welivesecurity.com/wp-content/uploads/2018/09/ESET-LoJax.pdf https://www.welivesecurity.com/wp-content/uploads/2018/09/ES...
I don’t know why security-conscious people would willingly load a PDF but there you go.
- jl6 8y agoAre you saying PDFs are a threat? More so than a web page?
- applecrazy 8y agoSlightly OT, but you would be surprised at how much power PDFs have (especially when opened in Adobe Acrobat/Reader). I recently came across this monstrosity[1] on HN, and the author mentions this: > Scripts can supposedly do things like make arbitrary database connections, detect attached monitors, import external resources, and manipulate 3D objects. That's an unprecedented level of power for what is supposedly a simple document format. That being said, PDFs are only a threat when opened in a with support for these obscure APIs, such as Adobe's own readers. You (probably) will be fine opening untrusted PDFs in Chrome's PDF reader (PDFium) and Preview. [1]: https://github.com/osnr/horrifying-pdf-experiments https://github.com/osnr/horrifying-pdf-experiments
- ggm 8y agoYou should totes makes this a top level HN post!!!! (I typed in my statutory copied one line NeWS program back in the day too. Never again)
- JdeBP 8y agohttps://news.ycombinator.com/item?id=17915296 https://news.ycombinator.com/item?id=17915296
- emmelaich 8y agoThanks! I also heard it's got a email sender (and receiver?) inbuilt.
- syn0byte 8y agoNote; Chrome's PDF reader executes the nested JS in his breakout PDF game. IIRC, the only one that did support it. Not that PDFium is any worse than Adobe, but certainly not much better.
- aiCeivi9 8y agoThere were multiple vulnerabilities related to PDF parsing in Adobe/Acrobat Reader/, firefox (pdf.js) and document viewers(libpopler, Okular). Also, there was a "game of life" implementation in PostScript and you can expect same level of capabilities in PDF.
- coldacid 8y agoPostScript at least has the excuse that it _is_ a programming language (for assembling documents for printing, but still a proper programming language) while PDF is supposed to be a fixed document format. PDF has far too much power for what it is supposed to do. Microsoft got it right with (O)XPS -- none of that dynamic stuff that lets you do all kinds of naughty things to the system with a properly formed document like PDF can do.
- tinus_hn 8y agoThat of course depends on what you think it’s supposed to do. PDF is not just a representation of paper, you can for instance also build forms. It would be nice if there was a separate ‘static paper’ only extension/mime type but there isn’t.
- jlgaddis 8y ago> Microsoft got it right with (O)XPS -- none of that dynamic stuff that lets you do all kinds of naughty things to the system with a properly formed document like PDF can do. On the other hand, they also get it wrong with other things and we end up with SYSTEM-level compromises due to a vulnerability in a font!
- jki275 8y agoThe pdf format is essentially an executable. Whether or not the browser sandboxes it correctly is a matter of debate.