$ 108,791.3
€ 95,760.8
£ 80,361.5
¥ 15,550,258.6
CZK 2,375,563.0
BTC
-0.84 %
$ 2,552.56
€ 2,247.26
£ 1,885.36
¥ 364,797.6
CZK 55,748.3
ETH
-0.88 %
$ 2.35
€ 2.07
£ 1.74
¥ 335.87
CZK 51.34
XRP
-1.08 %
$ 0.2884
€ 0.2539
£ 0.2130
¥ 41.23
CZK 6.31
XLM
-2.06 %
/?pid=1502

Updated:11:52 AM EDT May 23


this is ggmania.com subsite Hacker Discovers Adobe PDF Back Doors - TechAmok

Hacker Discovers Adobe PDF Back Doors - [security]
05:30 PM EDT - Sep,16 2006 - post a comment

Today's exploit comes to us from Adobe Acrobat Reader. It looks as though there are a couple of backdoors in even the fully patched and latest versions. A British security researcher has figured out a way to manipulate legitimate features in Adobe PDF files to open back doors for computer attacks.  David Kierznowski, a penetration testing expert specializing in Web application testing, has released proof-of-concept code and rigged PDF files to demonstrate how the Adobe Reader program could be used to launch attacks without any user action.
The first back door (PDF), which eWEEK confirmed on a fully patched version of Adobe Reader, involves adding a malicious link to a PDF file. Once the document is opened, the target's browser is automatically launched and loads the embedded link.  At this point, it is obvious that any malicious code [can] be launched," Kierznowski said. The use of Web-based exploits to launch drive-by malware downloads is a well-known tactic and the discovery of PDF back doors is further confirmation that desktop programs have become lucrative targets for corporate espionage and other targeted attacks.

A second back door demo (PDF) presents an attack scenario that uses Adobe Systems' ADBC (Adobe Database Connectivity) and Web Services support. Kierznowski said the back door can be used to exploit a fully patched version of Adobe Professional. "The second attack accesses the Windows ODBC (on localhost), enumerates available databases and then sends this information to 'localhost' via the Web service. This attack could be expanded to perform actual database queries. Imagine attackers accessing your internal databases via a user's Web browser," he said.


Add your comment (free registrationrequired)

Short overview of recent news articles

May,23 2025 Windows 98 with a G41 Core 2 Duo System
May,23 2025 Disable These Windows Settings for Better FPS!
May,20 2025 I Got the Golden GPU from Dubai
May,19 2025 Windows 10 emergency update KB5061768 fixes BitLocker boot loops -
May,19 2025 2025 AUDI S5 AVANT // 0-100 100-200 TOP SPEED POV & SOUND
May,18 2025 Jurassic World Rebirth - Official 'Alert' Teaser Trailer (2025)
May,18 2025 F1 25 and F1 The Movie hand in hand
May,17 2025 Everyone is Cooling Their PC Wrong
May,16 2025 M5 KILLER? Testing the MERCEDES E63S AMG!
May,16 2025 Samsung Fully Reveals 5.8mm-Thick Galaxy S25 Edge
May,16 2025 Apple Intros New Accessibility Apps, Plus Accessibility "Labels"
May,16 2025 Americana - Official Trailer (2025) Sydney Sweeney, Halsey, Simon
May,16 2025 Aston Martin x Apple CarPlay Ultra - Next generation of automotive
May,15 2025 Google TAG deleted 23,000+ YouTube channels in January, February,
May,14 2025 NVIDIA GeForce Game Ready 576.40 WHQL Driver Released
May,13 2025 F1 - Official Trailer #2 (2025) Brad Pitt, Damson Idris, Kerry
May,11 2025 The Old Guard 2 - Official Trailer (2025) Charlize Theron, KiKi
May,11 2025 I think I know why Ryzen 9000 Series CPUs are Dying...(!)
May,10 2025 Is Windows Defender good enough in 2025?
May,09 2025 AMD Adrenalin 25.5.1 Driver Released for Doom: The Dark Ages
May,09 2025 Ripple SEC Grip OVER, XRP Freedom of USE, Market MODE BULL RUN
May,08 2025 "Is x86 Actually Screwed?" ft. Wendell of Level1 Techs -
May,07 2025 Android's New Design Guidelines Leaked
May,06 2025 Grand Theft Auto VI trailer #2
May,05 2025 Microsoft's Dirty Secret: Your Old PC is Now Trash!
May,04 2025 No Noise Cancelling? GOOD. Unboxing the nwm One Headphones & First
May,04 2025 NEW! 2025 Audi S5 (367hp) | 0-258 km/h acceleration
May,02 2025 Bugatti Bolide vs Nurburgring. 1825 HorsePower Insanity
May,01 2025 This will be the largest tech Yard Sale EVER! Insanely low prices on
May,01 2025 Skoda Kodiaq RS 245 // 0-100 100-200 TOP SPEED POV & SOUND
May,01 2025 Disable or Uninstall Windows Recall to Protect Your Data Privacy
May,01 2025 A new Alternative to Nextcloud? OpenCloud presented and local
Apr,29 2025 NVIDIA GeForce Hotfix Driver 576.26 Available
Apr,28 2025 2025 Porsche 911 992.2 GTS T HYBRID | SOUND 0-100 100-200 200-300 &
Apr,28 2025 We Made Perfect Thermal Paste in a Factory, ft. Der8auer | Made In
Apr,28 2025 Cyber Security Company CEO Arrested for Installing Malware on
Apr,27 2025 This Kid Made his Own Laptop and it's AMAZING!
Apr,26 2025 How is this SO CHEAP? - Ubiquiti Cloud Gateway Fiber
Apr,26 2025 Ripple president on stablecoins, Trump and tokenization
Apr,26 2025 T-Mobile Launches 5G Advanced
>> News Archive <<

TechAmok - Privacy Policy        loading time:6.02secs