<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Don&#8217;t Open That Doc!</title>
	<link>http://hackademix.net/2007/09/20/dont-open-that-doc/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Tue, 02 Dec 2008 12:38:16 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Tom Hamilton</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-7572</link>
		<dc:creator>Tom Hamilton</dc:creator>
		<pubDate>Fri, 04 Apr 2008 20:07:15 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-7572</guid>
		<description>Dear Giorgio, 
    I have a apple computer, with the "tiger system" will no script work with it and is it necessary (are there javascript problems that will affect my computer?)
thanks for your time.</description>
		<content:encoded><![CDATA[<p>Dear Giorgio,<br />
    I have a apple computer, with the &#8220;tiger system&#8221; will no script work with it and is it necessary (are there javascript problems that will affect my computer?)<br />
thanks for your time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: securology</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-421</link>
		<dc:creator>securology</dc:creator>
		<pubDate>Fri, 21 Sep 2007 09:55:50 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-421</guid>
		<description>&lt;strong&gt;Still more separation of code and data&lt;/strong&gt;

Separating code from data is a HUGE problem (possibly a root of all remote code execution evil). Here's more info, some of it new, some of it very old ...</description>
		<content:encoded><![CDATA[<p><strong>Still more separation of code and data</strong></p>
<p>Separating code from data is a HUGE problem (possibly a root of all remote code execution evil). Here&#8217;s more info, some of it new, some of it very old &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-420</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 21 Sep 2007 08:33:11 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-420</guid>
		<description>@&lt;b&gt;nap&lt;/b&gt;:
"Proper" PDF spam is a well known trend, &lt;a href="http://www.sophos.com/pressoffice/news/articles/2007/08/pdf-spam.html" target="_blank" rel="nofollow external" rel="nofollow"&gt;apparently declining these days&lt;/a&gt;, not necessarily an infestation vector.
Nevertheless, PDF as a malware vehicle is quite &lt;a href="http://www.news.com/New-virus-travels-in-PDF-files/2100-1001_3-271267.html" target="_blank" rel="external nofollow" rel="nofollow"&gt;old news&lt;/a&gt;, so malicious mail with an attachment exploiting either an old or a new PDF vulnerability wouldn't come as a big surprise.</description>
		<content:encoded><![CDATA[<p>@<b>nap</b>:<br />
&#8220;Proper&#8221; PDF spam is a well known trend, <a href="http://www.sophos.com/pressoffice/news/articles/2007/08/pdf-spam.html" target="_blank" rel="nofollow external" rel="nofollow">apparently declining these days</a>, not necessarily an infestation vector.<br />
Nevertheless, PDF as a malware vehicle is quite <a href="http://www.news.com/New-virus-travels-in-PDF-files/2100-1001_3-271267.html" target="_blank" rel="external nofollow" rel="nofollow">old news</a>, so malicious mail with an attachment exploiting either an old or a new PDF vulnerability wouldn&#8217;t come as a big surprise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nap</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-418</link>
		<dc:creator>nap</dc:creator>
		<pubDate>Fri, 21 Sep 2007 07:07:37 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-418</guid>
		<description>I've been getting spam as pdf files. Didn't open them because i guessed there was some virus in them (why else would you spam with pdfs?). If you want I can maybe recover some if you want to dissect them.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been getting spam as pdf files. Didn&#8217;t open them because i guessed there was some virus in them (why else would you spam with pdfs?). If you want I can maybe recover some if you want to dissect them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-417</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 21 Sep 2007 06:49:38 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-417</guid>
		<description>The video and the few details Petko added &lt;a href="http://http://www.gnucitizen.org/blog/0day-pdf-pwns-windows#comment-51015" target="_blank" rel="nofollow external" rel="nofollow"&gt;in this comment&lt;/a&gt; and later, may suggest that 
&lt;ol&gt;
&lt;li&gt;We're still in the cross-application request forgery domain, since &lt;strong&gt;it requires IE7&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;It shouldn't work on Vista (nor on any non-Windows OS, of course -- worth to be said for all those Microsoft zealots out there)&lt;/li&gt;
&lt;li&gt;It should be mitigated by using an alternate PDF renderer, such as &lt;a href="http://portableapps.com/apps/office/sumatra_pdf_portable" target="_blank" rel="nofollow external" rel="nofollow"&gt;Sumatra PDF Portable&lt;/a&gt; (open source) or &lt;a href="http://www.foxitsoftware.com/pdf/rd_intro.php" target="_blank" rel="nofollow external" rel="nofollow"&gt;Foxit Reader&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;</description>
		<content:encoded><![CDATA[<p>The video and the few details Petko added <a href="http://http://www.gnucitizen.org/blog/0day-pdf-pwns-windows#comment-51015" target="_blank" rel="nofollow external" rel="nofollow">in this comment</a> and later, may suggest that </p>
<ol>
<li>We&#8217;re still in the cross-application request forgery domain, since <strong>it requires IE7</strong></li>
<li>It shouldn&#8217;t work on Vista (nor on any non-Windows OS, of course &#8212; worth to be said for all those Microsoft zealots out there)</li>
<li>It should be mitigated by using an alternate PDF renderer, such as <a href="http://portableapps.com/apps/office/sumatra_pdf_portable" target="_blank" rel="nofollow external" rel="nofollow">Sumatra PDF Portable</a> (open source) or <a href="http://www.foxitsoftware.com/pdf/rd_intro.php" target="_blank" rel="nofollow external" rel="nofollow">Foxit Reader</a></li>
</ol>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fulippo</title>
		<link>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-415</link>
		<dc:creator>Fulippo</dc:creator>
		<pubDate>Fri, 21 Sep 2007 06:16:53 +0000</pubDate>
		<guid>http://hackademix.net/2007/09/20/dont-open-that-doc/#comment-415</guid>
		<description>"My advise for you is not to open any PDF files (locally or remotely)."
I think that adobe wouldn't agree with him.. ;)
As always, noScript seems to be the all-in-one solution for a web safe navigation but it can't be useful in a non-web contest where pdfs are often used. 
I would be curious to know what kind of vulnerability the pdf can use.. or maybe it's just a personal quest against Adobe?</description>
		<content:encoded><![CDATA[<p>&#8220;My advise for you is not to open any PDF files (locally or remotely).&#8221;<br />
I think that adobe wouldn&#8217;t agree with him.. ;)<br />
As always, noScript seems to be the all-in-one solution for a web safe navigation but it can&#8217;t be useful in a non-web contest where pdfs are often used.<br />
I would be curious to know what kind of vulnerability the pdf can use.. or maybe it&#8217;s just a personal quest against Adobe?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
