<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: 0day: PDF pwns Windows</title>
	<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/</link>
	<description>Cutting-edge Think tank &#124; Ethical Hacker Outfit</description>
	<pubDate>Mon, 12 May 2008 05:32:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119825</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 25 Apr 2008 14:01:40 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119825</guid>
		<description>thanks for the comment.</description>
		<content:encoded><![CDATA[<p>thanks for the comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wishi</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119824</link>
		<dc:creator>wishi</dc:creator>
		<pubDate>Fri, 25 Apr 2008 13:30:48 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119824</guid>
		<description>:-)

Every security professional has to chose the path between publishing and keeping secret exploits every day. It's uncommon to put 0days in Blogs, because that handles out the problem to the wrong guys: not to those, who want to fix the issue, but to those, trying to abuse it for malicious mails or so.

I'm nosy, too... but executable code in a pdf is as old as Methusalem. That's no 0day. That's a joke ;).

Have fun,
wishi</description>
		<content:encoded><![CDATA[<p>:-)</p>
<p>Every security professional has to chose the path between publishing and keeping secret exploits every day. It&#8217;s uncommon to put 0days in Blogs, because that handles out the problem to the wrong guys: not to those, who want to fix the issue, but to those, trying to abuse it for malicious mails or so.</p>
<p>I&#8217;m nosy, too&#8230; but executable code in a pdf is as old as Methusalem. That&#8217;s no 0day. That&#8217;s a joke ;).</p>
<p>Have fun,<br />
wishi</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adobe PDF 被發現零時差安全漏洞 &#124; 大砲開講</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119798</link>
		<dc:creator>Adobe PDF 被發現零時差安全漏洞 &#124; 大砲開講</dc:creator>
		<pubDate>Fri, 25 Apr 2008 08:38:17 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-119798</guid>
		<description>[...] GnuCitizen的pdp最近在他們的部落格張貼了一篇文章，是有關PDF檔案出現零時差安全漏洞。如果使用者開啟一個特別製作的PDF檔案，就可以讓攻擊者控制你的系統。請各位不要亂開啟來路不明的PDF檔案。 在這篇文章中，作者只展示了此安全漏洞，並宣稱已經獲得Adobe，但沒有公開驗證程式，以致於有些人發出質疑的聲音。 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] GnuCitizen的pdp最近在他們的部落格張貼了一篇文章，是有關PDF檔案出現零時差安全漏洞。如果使用者開啟一個特別製作的PDF檔案，就可以讓攻擊者控制你的系統。請各位不要亂開啟來路不明的PDF檔案。 在這篇文章中，作者只展示了此安全漏洞，並宣稱已經獲得Adobe，但沒有公開驗證程式，以致於有些人發出質疑的聲音。 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JohnFavorite.com &#187; Blog Archive &#187; 0day: PDF pwns Windows</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-117727</link>
		<dc:creator>JohnFavorite.com &#187; Blog Archive &#187; 0day: PDF pwns Windows</dc:creator>
		<pubDate>Tue, 01 Apr 2008 08:03:52 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-117727</guid>
		<description>[...] going through the [Full-disclosure] mailing list I came across this gem. It seems as though Petko Petkovhave over at GNUCITIZEN found a serious flaw in the way Adobe [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] going through the [Full-disclosure] mailing list I came across this gem. It seems as though Petko Petkovhave over at GNUCITIZEN found a serious flaw in the way Adobe [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-114763</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Thu, 14 Feb 2008 22:47:13 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-114763</guid>
		<description>now that all the patches are out are you going to release some more details?</description>
		<content:encoded><![CDATA[<p>now that all the patches are out are you going to release some more details?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Inking&#8217;s Blog &#187; Google GMail E-mail Hijack Technique</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-108296</link>
		<dc:creator>Inking&#8217;s Blog &#187; Google GMail E-mail Hijack Technique</dc:creator>
		<pubDate>Sun, 03 Feb 2008 04:56:58 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-108296</guid>
		<description>[...] my disclosure policy regarding this vulnerability and the one disclosed several days ago concerning PDF. Let’s say that it is just one of my social [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] my disclosure policy regarding this vulnerability and the one disclosed several days ago concerning PDF. Let’s say that it is just one of my social [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Onlinespiele</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-83384</link>
		<dc:creator>Onlinespiele</dc:creator>
		<pubDate>Sat, 08 Dec 2007 17:27:06 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-83384</guid>
		<description>Are there any reactions from Adobe?</description>
		<content:encoded><![CDATA[<p>Are there any reactions from Adobe?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Mozilla Firefox 2.0.0.8 Universal XSS Zayıflığı WWW~TR-SECURiTY~COM:</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76418</link>
		<dc:creator>&#187; Mozilla Firefox 2.0.0.8 Universal XSS Zayıflığı WWW~TR-SECURiTY~COM:</dc:creator>
		<pubDate>Sat, 24 Nov 2007 16:08:52 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76418</guid>
		<description>[...] GNUCITIZEN yazarlarından pdp yine bir universal XSS zayıflığı bulmuş.Universal derken, genel olarak bir uygulamadan kaynaklanan ve her yerde geçerli olan anlamına gelmektedir.Örneğin yakın zamanda yine pdp Adobe Acrobat PDF dökümanlarını açarken meydana gelen bir universal XSS daha bulmuştu. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] GNUCITIZEN yazarlarından pdp yine bir universal XSS zayıflığı bulmuş.Universal derken, genel olarak bir uygulamadan kaynaklanan ve her yerde geçerli olan anlamına gelmektedir.Örneğin yakın zamanda yine pdp Adobe Acrobat PDF dökümanlarını açarken meydana gelen bir universal XSS daha bulmuştu. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sally</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76345</link>
		<dc:creator>Sally</dc:creator>
		<pubDate>Sat, 24 Nov 2007 10:48:11 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76345</guid>
		<description>Have you all noticed that the spammer's choice of delivery has become PDF attachments?

The attached PDF usually contains stock quotes.</description>
		<content:encoded><![CDATA[<p>Have you all noticed that the spammer&#8217;s choice of delivery has become PDF attachments?</p>
<p>The attached PDF usually contains stock quotes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sally</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76344</link>
		<dc:creator>Sally</dc:creator>
		<pubDate>Sat, 24 Nov 2007 10:44:27 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-76344</guid>
		<description>This explains why spammers have now switched to sending their emails with a PDF attachment.
Usually the PDF attachment contains an embedded image of a stock quote or something stupid like that. Lately I have been openning these out of curiousity but it seems we should not.</description>
		<content:encoded><![CDATA[<p>This explains why spammers have now switched to sending their emails with a PDF attachment.<br />
Usually the PDF attachment contains an embedded image of a stock quote or something stupid like that. Lately I have been openning these out of curiousity but it seems we should not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ggman</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-71646</link>
		<dc:creator>ggman</dc:creator>
		<pubDate>Thu, 15 Nov 2007 23:45:22 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-71646</guid>
		<description>@cyanid-E

I opened your pdf on a linux system
via:

1. adobe firefox plugin
2. adobe reader 8.1.1 ("Adobe strongly recommends upgrading to Adobe Reader 8.1.1")

and evolution offered me to send an email to guys with really strange email adresses:

1. "windows/system32/calc.exe" 
2. test%.. 

- quite scary -</description>
		<content:encoded><![CDATA[<p>@cyanid-E</p>
<p>I opened your pdf on a linux system<br />
via:</p>
<p>1. adobe firefox plugin<br />
2. adobe reader 8.1.1 (&#8221;Adobe strongly recommends upgrading to Adobe Reader 8.1.1&#8243;)</p>
<p>and evolution offered me to send an email to guys with really strange email adresses:</p>
<p>1. &#8220;windows/system32/calc.exe&#8221;<br />
2. test%.. </p>
<p>- quite scary -</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: \-=[WHK]=-// &#187; Archive &#187; Explicación del comando de ejecución arbitraria en documentos PDF</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-71511</link>
		<dc:creator>\-=[WHK]=-// &#187; Archive &#187; Explicación del comando de ejecución arbitraria en documentos PDF</dc:creator>
		<pubDate>Thu, 15 Nov 2007 18:55:34 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-71511</guid>
		<description>[...] http://www.gnucitizen.org/blog/0day-pdf-pwns-windows http://secunia.com/advisories/26201/ [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] <a href="http://www.gnucitizen.org/blog/0day-pdf-pwns-windows" rel="nofollow">http://www.gnucitizen.org/blog.....ns-windows</a> <a href="http://secunia.com/advisories/26201/" rel="nofollow">http://secunia.com/advisories/26201/</a> [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: V0lTr4n Bl0G &#187; El Adobe Reader tiene un serio agujero de seguridad</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-69929</link>
		<dc:creator>V0lTr4n Bl0G &#187; El Adobe Reader tiene un serio agujero de seguridad</dc:creator>
		<pubDate>Tue, 13 Nov 2007 02:20:05 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-69929</guid>
		<description>[...] Según el hacker Petko Petkov (Gray hat), existe un agujero de seguridad en Adobe Reader, que con solo abrir un PDF manipulado un hacker podría ejecutar un codigo malicioso en nuestros PCs, no dando detalles de la vulnerabilidad.Petkov ha confirmado que este bug afecta a los Windows XP SP2 con las últimas versiones de Adobe Reader 8.1, 8.0 y 7, aunque no se descarta que otras versiones de Windows estén afectadas. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Según el hacker Petko Petkov (Gray hat), existe un agujero de seguridad en Adobe Reader, que con solo abrir un PDF manipulado un hacker podría ejecutar un codigo malicioso en nuestros PCs, no dando detalles de la vulnerabilidad.Petkov ha confirmado que este bug afecta a los Windows XP SP2 con las últimas versiones de Adobe Reader 8.1, 8.0 y 7, aunque no se descarta que otras versiones de Windows estén afectadas. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: XT12D</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-68207</link>
		<dc:creator>XT12D</dc:creator>
		<pubDate>Fri, 09 Nov 2007 19:34:48 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-68207</guid>
		<description>Bad analogy, Adrian, A better one would be, "Why not hand out vials of HIV tainted blood in the hopes that some freelance doctor will find a cure?"</description>
		<content:encoded><![CDATA[<p>Bad analogy, Adrian, A better one would be, &#8220;Why not hand out vials of HIV tainted blood in the hopes that some freelance doctor will find a cure?&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0day vulnerability in PDF files could break your windows box &#124; AXT Magazine</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-67439</link>
		<dc:creator>0day vulnerability in PDF files could break your windows box &#124; AXT Magazine</dc:creator>
		<pubDate>Thu, 08 Nov 2007 01:56:12 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-67439</guid>
		<description>[...] under certain circumstances, a PDF file could remote execute an application on the host machine. The demo video shows how two pdf files, stored on local drive, once they&#8217;re open, can launch another [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] under certain circumstances, a PDF file could remote execute an application on the host machine. The demo video shows how two pdf files, stored on local drive, once they&#8217;re open, can launch another [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 新一代病毒感染途徑-PDF &#171; Jiunn&#8217;s mind + information collection</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65820</link>
		<dc:creator>新一代病毒感染途徑-PDF &#171; Jiunn&#8217;s mind + information collection</dc:creator>
		<pubDate>Tue, 06 Nov 2007 07:47:52 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65820</guid>
		<description>[...] 2007/09/20 PDF pwns Windows這篇文章。 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 2007/09/20 PDF pwns Windows這篇文章。 [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deeprunner</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65222</link>
		<dc:creator>Deeprunner</dc:creator>
		<pubDate>Mon, 05 Nov 2007 04:44:14 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65222</guid>
		<description>Very Informative and I see We still can't get along apparently, oh well.  But, being obviously on the lower end of the knowledge curve in this arena...Can any of you human beings tell me what you think of this link's usefullness regarding these kind of issues? -Vegas</description>
		<content:encoded><![CDATA[<p>Very Informative and I see We still can&#8217;t get along apparently, oh well.  But, being obviously on the lower end of the knowledge curve in this arena&#8230;Can any of you human beings tell me what you think of this link&#8217;s usefullness regarding these kind of issues? -Vegas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: electrobrain &#187; Blog Archive &#187; Kritische Schwachstelle in &#8216;Adobe Reader&#8217;</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65013</link>
		<dc:creator>electrobrain &#187; Blog Archive &#187; Kritische Schwachstelle in &#8216;Adobe Reader&#8217;</dc:creator>
		<pubDate>Sun, 04 Nov 2007 13:36:53 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-65013</guid>
		<description>[...] Originalmeldung: http://www.gnucitizen.org/blog/0day-pdf-pwns-windows [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Originalmeldung: <a href="http://www.gnucitizen.org/blog/0day-pdf-pwns-windows" rel="nofollow">http://www.gnucitizen.org/blog.....ns-windows</a> [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-61446</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Thu, 25 Oct 2007 13:05:36 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-61446</guid>
		<description>Great Site - really useful information!n</description>
		<content:encoded><![CDATA[<p>Great Site - really useful information!n</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nochmal Sicherheitslcke im Adobe Reader - wunderkessel.de - die Thermomix-Community</title>
		<link>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-61192</link>
		<dc:creator>Nochmal Sicherheitslcke im Adobe Reader - wunderkessel.de - die Thermomix-Community</dc:creator>
		<pubDate>Wed, 24 Oct 2007 17:19:27 +0000</pubDate>
		<guid>http://www.gnucitizen.org/blog/0day-pdf-pwns-windows/#comment-61192</guid>
		<description>[...] und ggf. die vollstaendige Kontrolle ueber das System erlangen.  Quellen:  Originalmeldung: 0day: PDF pwns Windows &#124; GNUCITIZEN CVE-2007-5020: National Vulnerability Database (CVE-2007-5020) Security Tracker: [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] und ggf. die vollstaendige Kontrolle ueber das System erlangen.  Quellen:  Originalmeldung: 0day: PDF pwns Windows | GNUCITIZEN CVE-2007-5020: National Vulnerability Database (CVE-2007-5020) Security Tracker: [&#8230;]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
