Author Topic: PDF still insecure  (Read 3923 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
PDF still insecure
« on: March 01, 2007, 01:23:11 PM »
Hi malware fighters,

Opening up PDF files with Adobe can be dangerous, via file//URL's javascript can enable cross scripting attacks on machines that store PDF files, and a means to steal data. Look for vulnerabilities on this page with various tests: http://www.gnucitizen.org/projects/pdf-strikes-back/poc.htm

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48630
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: PDF still insecure
« Reply #1 on: March 01, 2007, 02:18:21 PM »
Wordperfect Lightning opens my PDF's and that doesn't seen to make me vulnerable....
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline OrangeCrate

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 798
Re: PDF still insecure
« Reply #2 on: March 02, 2007, 06:32:18 PM »
Wordperfect Lightning opens my PDF's and that doesn't seen to make me vulnerable....

Holy smokes Bob, they just released the beta a couple of days ago didn't they? If you're not careful, you're going to get so many things stuffed into that box, that's it's going to explode. (The term "blivet" comes to mind  :))

In Open Office, I create a lot of PDF files on the fly, and I read PDF files with the current version of Adobe Reader from the Linux repositories, which is 7. But I do have version 8 installed in my windows partition, though I very seldom use it.

I'm not concerned in Linux, but it's certainly something to keep in mind in Windows, and users there should pay attention to this, if they use Adobe often.

Polonus, I wasn't aware of these vulnerabilities. Thanks for posting this. As always, your posts are very interesting.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48630
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: PDF still insecure
« Reply #3 on: March 02, 2007, 08:06:40 PM »
Quote
Holy smokes Bob, they just released the beta a couple of days ago didn't they? If you're not careful, you're going to get so many things stuffed into that box, that's it's going to explode.
The 1.3 Tetra bytes of storage still has a long way to go before it needs to be increased.  :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline OrangeCrate

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 798
Re: PDF still insecure
« Reply #4 on: March 02, 2007, 08:33:31 PM »
...Tetra bytes...

Ya, I know what a tetra is, and I'm pretty sure they don't byte.

http://en.wikipedia.org/wiki/Tetra
« Last Edit: March 03, 2007, 11:57:37 AM by OrangeCrate »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48630
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: PDF still insecure
« Reply #5 on: March 02, 2007, 08:56:47 PM »
Same tetra but a different byte.....  :)
http://en.wikipedia.org/wiki/Terabyte
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline OrangeCrate

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 798
Re: PDF still insecure
« Reply #6 on: March 02, 2007, 09:03:47 PM »
Same tetra but a different byte.....  :)
http://en.wikipedia.org/wiki/Terabyte

Oh, tera, not tetra. Sorry, I got mixed up. You know though, I don't think teras byte either, but I know these do...

http://en.wikipedia.org/wiki/Piranha

 ;D

All joking aside Bob, I assume that 1.3 terabytes is the sum total of all your hard drives? Must be nice...
« Last Edit: March 03, 2007, 11:57:11 AM by OrangeCrate »

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: PDF still insecure
« Reply #7 on: March 03, 2007, 08:22:46 AM »
Foxit reader seems to be OK, and it's much lighter than Adobe.

http://www.foxitsoftware.com/
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!