티스토리 뷰

- Link

 

So what is the problem?
We investigate the following question: How dangerous are permitted changes in certified documents?. To answer this question we systematically analyze the allowed modifications in certified documents and reveal two new vulnerabilities abusing flaws in the PDF specification: Evil Annotation Attack (EAA) and Sneaky Signature Attack (SSA). These vulnerabilities allow an attacker to change the visible content of a PDF document by displaying malicious content over the certified content. Nevertheless, the certification remains valid and the application shows no warnings.

How bad is it?
We evaluated 26 PDF applications and were able to break the security of certified documents in 24 of them. Additionally, we analyzed 26 applications to determine whether the permissions for adding annotations and signatures, as defined in the PDF specification, were implemented correctly. We show that for 11 of 26 applications, a permission mismatch exists.

The detailed results of our study can be found in the Evaluation and in our Paper (S&P'21).

Code Injection Attack on Adobe: Only certified documents may execute high privileged JavaScript code in Adobe products. For example, a high-level JavaScript can call an arbitrary URL without user confirmation to deanonymize a user. Our research reveals that such code is also executed if it is added as an allowed incremental update. We are the first to reveal that this behavior allows attackers to directly embed malicious code into a certified document.

 

02_Contract_cert_p2_SSA_sig-field_added_high_priv_JS_added_manipulated.pdf
0.02MB
01_Contract_cert_p3_EAA_FreeText_AMOUNT_manipulated.pdf
1.34MB
01_Contract_cert_p3_EAA_annot_added_high_priv_JS_added_manipulated.pdf
0.02MB
01_Contract_cert_p2_SSA_v1_sig-field_added_signed_manipulated.pdf
1.40MB

 

 

 

'보안 > 악성코드' 카테고리의 다른 글

Stuxnet 문서  (0) 2010.10.28
mscorsvw.exe  (0) 2010.03.03
[Borland] MIDAS.Dll  (0) 2010.01.13
Hacking Windows File Protection [펌 : bitsum.com]  (0) 2009.10.22
Clubfos 다운로드 매니저 - 설치되는 애드웨어 늘었다  (0) 2009.10.07
공지사항
최근에 올라온 글
최근에 달린 댓글
Total
Today
Yesterday
«   2024/05   »
1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31
글 보관함