jonny,
@jonny@neuromatch.social avatar

Someone who i adore (and don't think wants to be identified) shared with me this wonderful document, so i am sharing with you:

"Insecure features in PDFs"

https://web-in-security.blogspot.com/2021/01/insecure-features-in-pdfs.html

I had wondered about attack vectors using the self-editing and action chain features in , and i am more than thrilled to see infosec ppl demonstrating them formally

jonny,
@jonny@neuromatch.social avatar

one thing i have played with is PDFs being able to expose intra-document references, and reference external files in the local filesystem - this is how tools for links between PDF documents work that you can access from some LaTeX plugins. I have wondered how that would allow for probing local filesystems in combination with the form submission and email sending features in PDF that are sometimes enabled in readers, and i guess now i know.

jonny,
@jonny@neuromatch.social avatar

they also don't seem to be considering the obfuscation techniques that are also widespread in PDFs, the way that streams can be executed to yield javascript without needing to look like js to the usual PDF introspection libraries. at least so far, i'm not to the end yet

jonny,
@jonny@neuromatch.social avatar

this one is the funniest one

rmr,
@rmr@openbiblio.social avatar

@jonny
Whenever I read "code execution" this image pops up in my mind:

jonny,
@jonny@neuromatch.social avatar

@rmr is that lord quas or who is that

rmr,
@rmr@openbiblio.social avatar

@jonny
I have to admit, I didn't even know Lord Quas (https://en.wikipedia.org/wiki/Quasimoto ?). This picture of the poor code being executed is from Pixabay.

jonny,
@jonny@neuromatch.social avatar

@rmr https://youtu.be/U8C4w_bkP8k
I make your whole life backwards cause I'm the illa fiend
Ready to put ya head in the guillotine

also the drawing just looks like a poor lil quas

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tacticalgear
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • magazineikmin
  • modclub
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • ngwrru68w68
  • JUstTest
  • everett
  • tester
  • cubers
  • normalnudes
  • thenastyranch
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • megavids
  • lostlight
  • All magazines