5 ms·
Intriguing article about dissection of an advanced piece of malware that exploits a 0day PDF vulnerability. The punchline comes at the bottom of the article, wh
by justanother 14y ago
Intriguing article about dissection of an advanced piece of malware that exploits a 0day PDF vulnerability. The punchline comes at the bottom of the article, which instructs us to click a link to read a PDF for more information.
- lispm 14y agoThe vulnerability is in Adobe Reader. PDF is a file format and there are other readers.
- cschmidt 14y agoAre other readers more secure? Which would you recommend? I'm sure Adobe Reader gets more attention from the bad guys, because of market share. Is Apple's Preview any better (that's what I usually use)?
- willvarfar 14y agoHave you looked at Mozilla's Javascript PDF renderer? By rendering in the hardened Javasccript VM, it dramatically reduces attack surface.
- Sarkie 14y agoI use Chrome usually, just assign .pdf to load as a file:\\ but if that doesn't render. I'll try my SumatraPDF http://blog.kowalczyk.info/software/sumatrapdf/free-pdf-reader.html http://blog.kowalczyk.info/software/sumatrapdf/free-pdf-read... don't load if you don't like yellow!
- sbarre 14y agoAdobe Reader is to PDF documents in the same way that Internet Explorer is to HTML pages... Exploits are designed to target and exploit the consuming application of the malicious file, and are not executable by the file format itself (in these particular cases at least) in any arbitrary application that can open the file. So odds are that a 0-day exploit of Adobe Reader using a specially crafted PDF will have no effect in Apple's Preview app, or another PDF viewer (unless the apps were all using an underlying shared library and that's where the exploit lived, but I don't think this is the case here).
- vy8vWJlco 14y agoIt's hard to beat a static PNG via the browser, rendered from Far Far Away, on Google's servers... https://docs.google.com/viewer?embedded=true&url=https://www.securelist.com/en/downloads/vlpdfs/themysteryofthepdf0-dayassemblermicrobackdoor.pdf https://docs.google.com/viewer?embedded=true&url=https:/... Given the volume of PDFs Google must render, I wonder if they have had any security issues from the service.
- Scaevolus 14y agoIt's very hard to write an exploit when executable, environment, and countermeasures are all unknown.
- kordless 14y agoYeah, because the image viewers are always secure, right? http://technet.microsoft.com/en-us/security/bulletin/MS09-062 http://technet.microsoft.com/en-us/security/bulletin/MS09-06...
- apendleton 14y agoAs far as this discussion is concerned, yes. Exploiting a vulnerability that requires specially-crafted images isn't practical if the images are being generated by Google. You would need to find a vulnerability in Google's PDF renderer that let you cause it to generate an image that contained an additional exploit mechanism that would take advantage of the GDI bug. Sounds highly improbable.
- dunham 14y agoI believe Adobe's Reader has more support 'extensions' to PDF (e.g. embedding flash or javascript) than Apple, and that these things are often attack vectors. Preview should be immune to these. Aside from that it's mostly market share - they're different code bases, so they'd need different attacks. There is a chance of buffer overflow issues in the font decoding, image decoding, certificate processing, etc. But outside of iOS, few people have made the effort to attack non-adobe PDF Readers. Something like Chrome or Firefox is likely to be the most secure choice. Firefox's PDF reader is written in javascript, and I believe chrome's is sitting in a process that can't do anything to your machine. But I tend to just use Preview for stuff I've downloaded, because it's fast and I like the UI.
- IheartApplesDix 14y agoNo, there are not. FoxIt and similar 3rd party readers are not any more secure.