Full Disclosure mailing list archives
Re: [WEB SECURITY]RE: Universal XSS with PDF files: highly dangerous
From: RSnake <rsnake () shocking com>
Date: Thu, 4 Jan 2007 08:38:31 -0800 (PST)
Last night I came up with a proof of concept to exploit this locally: http://ha.ckers.org/blog/20070103/pdf-xss-can-compromise-your-machine/ If you have Adobe 7.0 installed there is a at least one standard PDF installed on the local drive. Ouch. -RSnake http://ha.ckers.org/ http://sla.ckers.org/ http://ha.ckers.org/fierce/ On Thu, 4 Jan 2007, Larry Seltzer wrote:
"According to public reports, this vulnerability is addressed in AdobeAcrobat Reader 8.0." I've actually tested it. On Reader 8 Acrobat you get a messagebox that says "This operation is not allowed" Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.eweek.com/blogs/larry%5Fseltzer/ Contributing Editor, PC Magazine larryseltzer () ziffdavis com ---------------------------------------------------------------------------- The Web Security Mailing List: http://www.webappsec.org/lists/websecurity/ The Web Security Mailing List Archives: http://www.webappsec.org/lists/websecurity/archive/ http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous, (continued)
- Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous M . B . Jr . (Jan 08)
- Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous Jim Manico (Jan 09)
- Re: [WEB SECURITY] Universal XSS with PDF files: highly dangerous HASEGAWA Yosuke (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous Kristina Lein (Jan 05)
- Re: Universal XSS with PDF files: highly dangerous pdp (architect) (Jan 05)
- Re: Universal XSS with PDF files: highly dangerous Stefano Di Paola (Jan 05)
- Re: Universal XSS with PDF files: highly dangerous The Anarcat (Jan 08)
- Re: Universal XSS with PDF files: highly dangerous Matthew Flaschen (Jan 08)
- Re: Universal XSS with PDF files: highly dangerous Juha-Matti Laurio (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous Larry Seltzer (Jan 04)
- Re: [WEB SECURITY]RE: Universal XSS with PDF files: highly dangerous RSnake (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous Larry Seltzer (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous Juha-Matti Laurio (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous T Biehn (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous pdp (architect) (Jan 04)
- Re: Universal XSS with PDF files: highly dangerous T Biehn (Jan 04)