ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

PDF threat worse than first thought

Joris Evers CNET News.com

Published: 05 Jan 2007 08:24 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A recently discovered security weakness in the widely used Acrobat Reader software could put net users at more risk than previously thought, experts warned on Thursday.

Initially, security professionals thought that the problem was restricted and exposed only web-related data or could support phishing scams. Now it has been discovered that miscreants could exploit the problem to access all information on a victim's hard disk drive, said web security specialists at WhiteHat Security and SPI Dynamics.

Key to increased access is where hostile links point. When the issue was first discovered, experts warned of links with malicious JavaScript to PDF files hosted on websites. While risky, this actually limits the attacker's access to a PC. It has now been discovered that those limits can be removed by directing a malicious link to a PDF file on a victim's PC.

"This means any JavaScript can access the user's local machine," Billy Hoffman, lead engineer at SPI Dynamics, said in an emailed statement. "Depending on the browser, this means the JavaScript can read the user's files, delete them, execute programs, send the contents to the attacker, etc. This is much worse than an attack in the remote zone."

By contrast, a link to a PDF hosted on a website with malicious JavaScript code would run on the user's machine with limited access, or the "remote zone", Hoffman said. For example, script code in a link to a PDF on "bank.com" would be able to communicate with bank.com and access its cookies, he said. Such a standard cross-site-scripting attack could allow account hijacks, for example.

The security problem exists because the web browser plug-in of the Adobe Systems' Acrobat Reader allows JavaScript code appended to links to PDF files to run once the link is clicked, said Jeremiah Grossman, chief technology officer at WhiteHat Security.

For an attack to work, a malicious link has to point to an existing PDF file on the web or on the target system. PDFs are abundant on the net and finding one on a local system isn't hard; a sample PDF file comes with Acrobat Reader and is installed in a predictable location on PCs, Grossman said.

The security problem was first disclosed at the Chaos Computer Club conference in Germany over the holidays in a paper by Stafano Di Paola and Giorgio Fedon. The extended scope of the issue was publicised late on Wednesday by a hacker using the moniker "RSnake".

Adobe is aware of the claims that an attack could have broader implications, but had not verified the issue, a company representative said in an emailed statement on Thursday.

"Based upon info we have, Flash Player, Reader and modern browsers should restrict such an exploit, but we haven't completed our evaluation of all possible scenarios," the representative said.

To mitigate the threat, users can upgrade to Adobe Reader 8, the latest version of the Adobe software released last month. Adobe is also working on updates to previous versions that will resolve this issue, the company has said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
148 out of 157 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Webmaster-London- Contract- IMMEDIATE START

I am urgently looking to fill a Webmaster contract role - HTML Validation, link verification DDA, CSS, JavaScript, IIS, .Net World leading ...

HTML CSS Dreamweaver - Creative Web Designer role - Berkshire

To be considered for this role, the designer must have the following skills: Advanced knowledge of HTML, JavaScript and CSS Basic knowledge of ...

Perl Developer-Perl, JavaScript, MySQL, SOAP, Apache, Perl Developer

You must have extensive experience developing in Perl in a web environment ideally hosted on Linux or UNIX servers. You will have excellent ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment