Skip to navigation
   
Davey Winder's Blog

Chaos Computer Club explodes Adobe PDF security bomb

By Davey Winder in Editorial

Posted in Adobe on January 5, 2007 at 1:32 am

Permalink | Author Profile

Adobe Reader has been pretty much single handedly responsible for ensuring PDF has become the de facto portable document publishing format on the web. It could also single handedly allow a universal cross scripting (XSS) exploit to compromise your website and your business. How serious is this particular vulnerability? Well, how serious does the fact that any site hosting a .pdf file could be at risk from attack.

As Stefano Di Paola and Giorgio Fedon revealed at the Chaos Computer Club in Berlin, the open parameters feature of the Adobe Reader browser plug-in allows for the arbitrary execution of JavaScript code on the client side, and that code could easily come with malicious intent. Indeed, Symantec has gone as far as stating in its security response blog that the

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

parental control migration science iPad terrorism VeriSign Windows Phone 7 Series fraud management Backlash family virtualisation payments Army hacking Mars Nexus ISP patch management virtual world Microsoft Developers Web Development ROFL MessageLabs digitise Networks Intel Madness transactional security Employment admin ecommerce Trousers meme Facebook support code smartphone PS3 Jobs storage OS services Blog computers Analysis SSL botnet Rant payment server Architecture YouTube Retail Paris Hilton worm Programming BOFH Browser Kill Switch Press avatar Study Palm standards social networking desktop service Lotus Big Brother Game Palm Pre VPN money Video Business School Pirate snooping tax ISPA malware network phishing lawsuit Bill Gates scan Energy graphics Microchip MSN XP Vista Blogging fun spam FBI green Patents Sex economics home survey prison Digg Data Centre credit crunch IP Parenting Twitter Recall Browsers Meh shopping rootkits Psion mail man-in-the-middle memory Cisco Death spending data protection Banned hypervisor technology office Yahoo Noro crime virus VM stupid BSI InfoSec e betting eBook credit card fraud open source Europe museum xmas SMS Russia monetisation remote working Voice Notebooks Experiment Amazon universe Opinion fake NASA Linux banks Military Addiction archiving recession Software Music USA Mobile Phone information Project computer Geeks Government Jesus Phone IDC Netbook Ballmer privacy remote disclosure Spotify Top 10 nightmare Google Earth global iPhone worker economy Marketing law GSM Finjan encryption library politics Porn Children biometrics Nintendo AMD environment poll trust Kaspersky CAPTCHA Steve Jobs Guardian Battery MSNBC Apps second life Research Review productivity Gartner Flash Advertising email stupidity Sony OCR Internet Explorer adware development IT holidays Application scareware wifi mobile Dell black hat Enterprise Digital Footprint chips Deal campaign virtual machine Top 500 Election compromise Texas Instruments GMail computing ID Theft work Johnny Depp Windows Kin Steve Ballmer tech linkedin staffing Licensing Android documentation report debian games patent iPhone 3G Eee PC dumb App Silverlight security scam iPod fool IBM Supercomputer Hack copyright App Store Performance computing web Media innovation Eee statistics Rumour symantec Gadget search books Internet President The Federation Google iPhone 3GS size Apple Education gadgets millions Windows 7 Funny gaming students EU McKinnon ASUS Trojan Psychic China help world of warcraft Tesco Michael Jackson console hoax acquisition carbon copy Conference data Scotland NBC Mafia DNS news RAM HP web 2.0 Olympics Kindle Harry Potter teleworking Gateway Texting Health RATM outsourcing Firefox printing policy hubdub cloud Space christmas Beta hardware banking workplace earth hour Acer broadband football HPC hacker surveys MiniBook exploit sick Mobile Phones theft Obama Zango e-commerce Adobe
Advertisement
Advertisement