|
|
Hacker Discovers Adobe PDF Back Doors - TechAmok
Hacker Discovers Adobe PDF Back Doors - [security] 05:30 PM EDT - Sep,16 2006 - post a comment Today's exploit comes to us from Adobe Acrobat Reader.
It
looks as though there are a couple of backdoors in even the fully patched
and latest versions. A British security researcher has figured out a way to
manipulate legitimate features in Adobe PDF files to open back doors for
computer attacks. David Kierznowski, a penetration testing expert
specializing in Web application testing, has released proof-of-concept code and
rigged PDF files to demonstrate how the Adobe Reader program could be used to
launch attacks without any user action.
The
first back door (PDF), which eWEEK confirmed on a fully patched version of
Adobe Reader, involves adding a malicious link to a PDF file. Once the document
is opened, the target's browser is automatically launched and loads the embedded
link. At this point, it is obvious that any malicious code [can] be
launched," Kierznowski said. The use of Web-based exploits to launch drive-by
malware downloads is a well-known tactic and the discovery of PDF back doors is
further confirmation that desktop programs have become
lucrative targets for corporate espionage and other
targeted attacks.
A second
back
door demo (PDF) presents an attack scenario that uses Adobe Systems' ADBC
(Adobe Database Connectivity) and Web Services support. Kierznowski said the
back door can be used to exploit a fully patched version of Adobe Professional.
"The second attack accesses the Windows ODBC (on localhost), enumerates
available databases and then sends this information to 'localhost' via the Web
service. This attack could be expanded to perform actual database queries.
Imagine attackers accessing your internal databases via a user's Web browser,"
he said.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
|
Feb,11 2026 Apple releases iOS 26.3 and iPadOS 26.3 to the public Feb,11 2026 T-Mobile Announces Live Audio Language Translation as a Network Feb,10 2026 Windows 11 26H1 Drops Exclusively on New Snapdragon X2 Devices - No Feb,10 2026 Fake 7-Zip downloads are turning home PCs into proxy nodes Feb,10 2026 Microsoft Patch Tuesday February 2026 - 54 Vulnerabilities Fixed, Feb,10 2026 Snapdragon X2 Elite Early - Performance Preview Feb,10 2026 AI Chat App Exposes 300 Million Messages from 25 Million Users Feb,09 2026 My Kids can Pick ANY Phone They Want For a Present Feb,09 2026 Microsoft Removes Printer Drivers in Windows 11 Update - What You Feb,09 2026 Apple's Next AirPods Pro Will Literally See the World Around You Feb,09 2026 Beware of Apple Pay Phishing Attack that Aims to Steal Your Payment Feb,08 2026 NASA to Allow Astronauts to Bring Smartphones to Space Feb,08 2026 AT&T Launches New Samsung Phone for Kids Feb,07 2026 Headphones with Noise Cancelling that Don't Stick in your Ear - Feb,07 2026 Microsoft Just Killed Your Old Printer: Legacy Drivers Officially Feb,06 2026 RenEngine Loader and HijackLoader Duo Infects Over 400,000 Gamers in Feb,06 2026 EpsteIn Tool: Check If Your LinkedIn Contacts Appear in 3.5 Million Feb,05 2026 Bitcoin's $64,000 Reality vs. $87K+ Production Costs Sparks Feb,05 2026 Crypto Analyst Issues Urgent 'Final Warning' on XRP: Claims Feb,04 2026 AI-Powered Breach: Hacker Claims AWS Kingdom in Under 10 Minutes Feb,04 2026 Microsoft Axes Standalone SharePoint and OneDrive Plans in Push to Feb,04 2026 Nvidia's $100 billion OpenAI deal has seemingly vanished Feb,04 2026 The Best 14" Gaming Laptops Right Now Feb,04 2026 The Solution to the RAM Crisis is... DDR4??? Feb,03 2026 Google Meet can now join Microsoft Teams calls Feb,03 2026 The Devil Wears Prada 2 - Official Trailer (2026) Meryl Streep, Anne Feb,02 2026 *EPSTEIN HAD THE SEC SUE RIPPLE/XRP - HOLY SH*T | Gensler Worked For Feb,02 2026 Mozilla Firefox is making it super easy to turn off its generative Feb,01 2026 Windows 11 quietly gets a new security feature to protect system Feb,01 2026 WARNING: TRUMP & RIPPLE/XRP SECRET AGREEMENT AT DAVOS Feb,01 2026 China's new RAM company, CXMT, is selling RAM at $138 Feb,01 2026 Windows keeps a permanent record of every USB device you've ever Feb,01 2026 Intel Is BACK - Panther Lake Changes Everything Jan,31 2026 NVIDIA Releases GeForce Security Update Driver 582.28 for Legacy Jan,31 2026 AMD 'Zen 6' CCD Packs 12 Cores, 48 MB L3 Cache Jan,31 2026 Microsoft Set to Disable Legacy NTLM Authentication by Default in Jan,30 2026 NVIDIA GeForce 591.86 WHQL Driver Jan,30 2026 iOS 26.3-Important New iPhone Location Privacy Feature Coming Soon Jan,29 2026 I Made the Ultimate Steam Machine Before Valve Jan,29 2026 Wardriver - Official Trailer (2026) Dane DeHaan, Sasha Calle,
>> News Archive <<
| |
|