ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Adobe: No threat from PDF spam

Lynn Tan ZDNet Asia

Published: 16 Aug 2007 10:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

PDF spam, junk email with its message attached as a PDF file to get past spam filters, poses no security risk, says Adobe.

Responding to a query on whether PDF spam can embed malicious software, Erick Lee, a security engineer at Adobe, wrote in an email on Wednesday: "PDF is no more able to embed malware on an unsuspecting user's system than any other typical email attachment."

Over the last two months, security vendors have seen a spike in spam embedded within PDF documents. Last week, it was used in a large-scale "pump-and-dump" scam which reportedly caused a huge spike in spam levels, as well as the share price of the company highlighted in the PDF spam campaign.

According to the PDF-creation software maker, there is no hard evidence that such spam exposes users to any security risk.

"Although a nuisance, we have not verified an incident where PDF spam became a security issue," Lee said. "Users can be assured that PDF is still the de facto standard for more secure and dependable electronic information exchange."

Nonetheless, Lee added, the onus is on users to protect themselves. "[We] recommend that users exercise scepticism and caution when receiving unsolicited email communications requesting user action, such as opening attachments or clicking web links," he said.

In Symantec's latest report, released on Monday, the security vendor noted that PDF image spam, which started to emerge in June this year and is on the rise, accounted for between two and eight percent of all spam in July.

Ascertaining authenticity
One way a valid PDF sender can ensure that the recipient knows the file is authentic, is to use a certified document digital signature, said Lee.

The security engineer noted that the digital signature, when combined with Adobe Acrobat and Reader, will "provide additional validation of the author and content".

Lee said that, to ensure the security of the PDF document, the company has a Dynamic Link Library (DLL) file called PDF IFilter, which "enables the creation of software that analyses PDF files".

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

The PDF IFilter is used by security vendors, as well as search-engine companies, to scan the contents of PDF files. "For example, when a user searches for a PDF file on Google, they can click a found link to see the PDF file's contents in a HTML page," Lee explained.

Adobe said it is working with spam-filter companies to help prevent PDF spam from "getting through to inboxes" by implementing the PDF IFilter.

Details on potential vulnerabilities and their solutions are available on Adobe's website, and all documented security vulnerabilities and their solutions are distributed through the Adobe security-notification service.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
11 out of 11 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

IPT Support Engineer

Unity and Unity Connections Voicemail.voice and/or video networks using H.323 / SIP protocols QoS and prioritization techniques Networking directory ...

SPANISH 2nd LINE DESKTOP SUPPORT ENGINEER, Surrey, 25k

You will liaise with remote I.T.departments, IT managers, department heads and hardware and software vendors to resolve issues and queries that ...

Vmware / Wintel - Technical Consultant / Engineer - MCSE VCP Storage

Lead vendors at my client are Microsoft, VMware, Commvault, Ironport, HDS, Equallogic and Cisco. Technical Consultant / Consulting Engineer - Windows ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments