You are here: silicon.com > Software > Security Strategy

Security Strategy

Adobe PDF flaw 'more serious than first thought'

Hard drive data at risk too, say experts...

Tags: adobe acrobat, pdf, adobe, flaw

By Joris Evers

Published: 5 January 2007 08:30 GMT

A recently discovered security weakness in the widely used Acrobat Reader software could put net users at more risk than previously thought, experts have warned.

Initially, security professionals thought that the problem was restricted and exposed only web-related data or could support phishing scams. Now it has been discovered that miscreants could exploit the problem to access all information on a victim's hard drive, said web security specialists at SPI Dynamics and WhiteHat Security.

Key to increased access is where hostile links point. When the issue was first discovered, experts warned of links with malicious JavaScript to PDF files hosted on websites. While risky, this actually limits the attacker's access to a PC. It has now been discovered that those limits can be removed by directing a malicious link to a PDF file on a victim's PC.

Billy Hoffman, lead engineer at SPI Dynamics, said in an emailed statement: "This means any JavaScript can access the user's local machine. Depending on the browser, this means the JavaScript can read the user's files, delete them, execute programs, send the contents to the attacker, et cetera. This is much worse than an attack in the remote zone."

By contrast, a link to a PDF hosted on a website with malicious JavaScript code would run on the user's machine with limited access, or the "remote zone", Hoffman said. For example, script code in a link to a PDF on "bank.com" would be able to communicate with bank.com and access its cookies, he said. Such a standard cross-site-scripting attack could allow account hijacks, for example.

The security problem exists because the web browser plug-in of the Adobe Systems' Acrobat Reader allows JavaScript code appended to links to PDF files to run once the link is clicked, said Jeremiah Grossman, chief technology officer at WhiteHat Security.

For an attack to work, a malicious link has to point to an existing PDF file on the web or on the target system. PDFs are abundant on the net and finding one on a local system also isn't hard, a sample PDF file comes with Acrobat Reader and is installed in a predictable location on PCs, Grossman said.

The security problem was first disclosed at the Chaos Computer Club conference in Germany over the holidays in a paper by Stafano Di Paola and Giorgio Fedon. The extended scope of the issue was publicised by a hacker using the moniker "RSnake".

Adobe is aware of the claims that an attack could have broader implications but had not verified the issue, a company representative said in an emailed statement.

The representative said: "Based upon info we have, Flash Player, Reader and modern browsers should restrict such an exploit but we haven't completed our evaluation of all possible scenarios."

To mitigate the threat, users can upgrade to Adobe Reader 8, the latest version of the Adobe software released last month. Adobe is also working on updates to previous versions that will resolve this issue, the company has said.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?


  • Jobs
Sharepoint Developer Required in West Midlands

Knowledge of xhtml/CSS/JavaScript - Experience of writing cross browser code. A Sharepoint Developer is required by my West Midlands based client on ...

Flash / Actionscript Developer - 30-40k Gloucestershire URGENT

Adobe Photoshop and Flash design skills. Aware of modern web standards and cross-browser compatibility. XHTML, CSS, JavaScript and XML. Huxley ...

Software developer - excellent chance to learn new skills

Experience writing cross browser client side code, using XHTML, JavaScript and CSS. The software is built on XML, XSLT, CSS and JavaScript with C# ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: