Malware inside PDF Files
by Manuel Humberto Santander Pelaez (Version: 1)
There is an interesting trend of malware: Javascript Malware inside PDF files. Many people have not updated their programs to read PDF files (I have seen personally people with Adobe Reader 5 on their computers) and so they are exposed to old exploits.
There is an interesting analysis posted by Kimberly (http://stopmalvertising.com/malware-reports/analysis-of-wzzc_pdf-exploitjspdfkacnk) that shows a Obfuscated Javascript inside a PDF file taking advantage of CVE-2008-2992 and CVE-2009-0927. The Wepawet service (http://wepawet.iseclab.org) shows possible malware inside PDF files.
Please remember: if a new version for a software goes out and it does not affect your operation, please use it. It will help you to prevent future headaches.
-- Manuel Humberto Santander Peláez | http://twitter.com/manuelsantander | http://manuel.santander.name | msantand at isc dot sans dot org
Comments
"Obfuscated Javascript inside a PDF file"
Do you mean Java, or JavaScript, or both? (There is a difference.)
bjnord
Jul 4th 2010
1 decade ago
Manuel Humberto Santander Peláez
Jul 4th 2010
1 decade ago
For myself I use Foxit or xPDF and try to stay up to date, but haven't used Reader in a few years...
duodec
Jul 6th 2010
1 decade ago