<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The FORWARD project blog &#187; Foxit Reader</title>
	<atom:link href="http://blogs.ict-forward.eu/forward/tag/foxit-reader/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.ict-forward.eu/forward</link>
	<description>blogging on emerging and future threats</description>
	<lastBuildDate>Mon, 30 Jan 2012 09:09:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Exploiting PDF files, without a vulnerability</title>
		<link>http://blogs.ict-forward.eu/forward/exploiting-pdf-files-without-a-vulnerability/</link>
		<comments>http://blogs.ict-forward.eu/forward/exploiting-pdf-files-without-a-vulnerability/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 18:15:30 +0000</pubDate>
		<dc:creator>tsikudis</dc:creator>
				<category><![CDATA[security news]]></category>
		<category><![CDATA[Adobe Acrobat Reader]]></category>
		<category><![CDATA[Foxit Reader]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blogs.ict-forward.eu/forward/?p=720</guid>
		<description><![CDATA[Portable Document Format (PDF) files can be used to execute an embedded executable without exploiting any security vulnerabilities. These proof-of-concept PDF files targeting computers running Adobe Acrobat Reader or Foxit Reader PDF software, as Didier Stevens a security researcher warned, runs the embedded executable by launching a command that ultimately runs an executable. Researcher said [...]]]></description>
			<content:encoded><![CDATA[<p>Portable Document Format (PDF) files can be used to execute an embedded executable without exploiting any security vulnerabilities. These proof-of-concept PDF files targeting computers running Adobe Acrobat Reader or Foxit Reader PDF software, as Didier Stevens a security researcher warned, runs the embedded executable by launching a command that ultimately runs an executable.</p>
<p><span id="more-720"></span>Researcher <a href="http://blog.didierstevens.com/2010/03/29/escape-from-pdf/">said</a> that Adobe’s PDF Reader will block the file from  automatically opening but he warned that an attacker could use social  engineering tricks to get users to allow the file to be opened. With Foxit Reader there is no warning.</p>
<p>This kind of attack does not use JavaScript code and does not exploiting a vulnerability so neither disabling JavaScript neither patching Adobe Reader will prevent this.</p>
<p>A few days later another researcher Jeremy Conway <a href="http://www.sudosecure.net/archives/636">posted</a> an attack showing that PDFs are &#8220;wormable&#8221;. It’s possible to launch an attack internally from one PDF onto another  already existing PDF, raising the possible of a PDF worm.</p>
<p>Finally a further modified attack, showing how a single malicious PDF could infect an unlimited number of documents was <a href="http://www.sudosecure.net/archives/653">posted</a> by Jeremy.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.ict-forward.eu/forward/exploiting-pdf-files-without-a-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

