You know by now not to open unexpected email attachments, but what if someone that appears legit sends you a PDF? How harmful can it be? As it turns out, very. This week a harmless-looking invitation to a Nobel Prize ceremony was a nasty piece of business indeed. When saved to a hard drive and opened, it sets up a backdoor so that the bad guys can take over your PC at will, all while you think nothing is going on. What is troubling is that this isn’t new.
This PDF exploit has been around for several years, yet it seems that it doesn’t get much attention from the general public. The security community is all over it. Here is a collection of articles that appeared on SearchSecurity.com earlier this summer that tells corporate IT folks how to secure these type of files.
And here is a video screencast that shows you the exploit in its gory detail.
So why hasn’t word gotten out? Why hasn’t Adobe fixed this issue? Well, they try, but the structure of the PDF format itself makes it hard to secure. It even has the nasty habit of saving revisions, so some hackers can go in and review previous versions and redacted text.
...|
The next PDF you open may be your last You know by now not to open unexpected email attachments, but what if someone that appears legit sends you a PDF? How harmful can it be? As it turns out, |
|
Google's Chrome Adds Integrated PDF Reader
Google's Chrome beta channel has added an integrated PDF viewer for viewing Adobe Acrobat documents without leaving the browser. "To open a PDF document,
|
|
How To Open PDF Or Adobe PDF Attachment On The Web “I can't read my PDF files on my computer. How to do with it?” “What's wrong with my Firefox, which can't allow me to read PDF attachment? |
|
Adeptol Introduces Mobile Viewer with Support for More Than 300 File Formats The viewer supports out of box more than 300 file formats including Microsoft Office (2000, 2007, 2010) documents, Open Office documents, PDF, AutoCAD files |
|
Another day, another Adobe PDF Reader security hole Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, |