OMG WTF PDF – What you didn’t know about Acrobat

March 31, 2011 (at 11:30 a.m.) in Attack & Research

Ambiguities in the PDF specification means that no two PDF parsers will see a file in the same way. This leads to many opportunities for exploit obfuscation.

PDFs are currently the greatest vector for drive-by (malware installing) attacks and targeted attacks on business and government. A/V technology is extraordinarily poor at detecting these. The PDF format itself is so diverse and vague, that an A/V would need to be 100% bug-compatible with the parser in the vulnerable PDF reader.

Julia will also show some cool tricks like making a single PDF file that displays completely differently in several different readers.

Further reading or German TROOPERS: <a href="http://www.heise.de/security/meldung/27C3-Brandgefaehrliche-PDF-Dokumente-Update-1162122.html" target="_blank">heise.de</a> Further reading for English TROOPERS: <a href="http://www.h-online.com/security/news/item/27C3-danger-lurks-in-PDF-documents-Update-1162166.html" target="_blank">h-online.com</a>

Julia Wolf

Julia solves puzzles and finds the answers to the questions which no one knows the answers to.