<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Universal PDF XSS After Party</title>
	<atom:link href="http://www.gnucitizen.org/blog/universal-pdf-xss-after-party/feed/" rel="self" type="application/rss+xml" />
	<link>/blog/universal-pdf-xss-after-party/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 19:33:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Universal PDF XSS &#124; Forums Blog</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-122403</link>
		<dc:creator>Universal PDF XSS &#124; Forums Blog</dc:creator>
		<pubDate>Sun, 01 Jun 2008 13:40:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-122403</guid>
		<description>[...] in many new creative ways. I will be discussing this issue in my next podcast, till then read up on it here or at [...]</description>
		<content:encoded><![CDATA[<p>[...] in many new creative ways. I will be discussing this issue in my next podcast, till then read up on it here or at [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DReTeN</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-85524</link>
		<dc:creator>DReTeN</dc:creator>
		<pubDate>Wed, 12 Dec 2007 19:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-85524</guid>
		<description>you just gotta convince them to get the newest version of Acrobat. That's why there are updates and improved versions, to fix the bugs and vulnerabilities of previous editions.</description>
		<content:encoded><![CDATA[<p>you just gotta convince them to get the newest version of Acrobat. That&#8217;s why there are updates and improved versions, to fix the bugs and vulnerabilities of previous editions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edward</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-76346</link>
		<dc:creator>Edward</dc:creator>
		<pubDate>Sat, 24 Nov 2007 10:54:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-76346</guid>
		<description>We allow users to try our software by uploading documents to an application we host. Some of the uploaded documents can be seen and accessed by other users.

What kind of measures can we take so that users with older Acrobat versions are not compromised?</description>
		<content:encoded><![CDATA[<p>We allow users to try our software by uploading documents to an application we host. Some of the uploaded documents can be seen and accessed by other users.</p>
<p>What kind of measures can we take so that users with older Acrobat versions are not compromised?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-14187</link>
		<dc:creator>alex</dc:creator>
		<pubDate>Thu, 12 Apr 2007 20:07:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-14187</guid>
		<description>hi nice site.</description>
		<content:encoded><![CDATA[<p>hi nice site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robo de cookies en Myspace &#171; &#124; Seguridad01 &#124; TECNOLOGIAS Y SEGURIDAD INFORMÃTICA</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-6926</link>
		<dc:creator>Robo de cookies en Myspace &#171; &#124; Seguridad01 &#124; TECNOLOGIAS Y SEGURIDAD INFORMÃTICA</dc:creator>
		<pubDate>Thu, 15 Mar 2007 15:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-6926</guid>
		<description>[...] Robo de cookies en&#160;Myspace  SÃ­, y esque ni el santo grial se libra (Universal Google XSS). Ahora le toca a las cookies , XSS y a myspace Â¿buena combinaciÃ³n no?. El usuario rMrGvG mÃ¡s conocidos por sus advisors a importantes pÃ¡ginas y CMS. Ha descubierto que es posible robar cookies de usuarios de myspace a traves de ataques XSS y CSS (Cross Site Scripting). [...]</description>
		<content:encoded><![CDATA[<p>[...] Robo de cookies en&nbsp;Myspace  SÃ­, y esque ni el santo grial se libra (Universal Google XSS). Ahora le toca a las cookies , XSS y a myspace Â¿buena combinaciÃ³n no?. El usuario rMrGvG mÃ¡s conocidos por sus advisors a importantes pÃ¡ginas y CMS. Ha descubierto que es posible robar cookies de usuarios de myspace a traves de ataques XSS y CSS (Cross Site Scripting). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: erez</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2442</link>
		<dc:creator>erez</dc:creator>
		<pubDate>Tue, 16 Jan 2007 14:08:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2442</guid>
		<description>seems to be fixed with the latest 7.0.9 patch...</description>
		<content:encoded><![CDATA[<p>seems to be fixed with the latest 7.0.9 patch&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2252</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 12 Jan 2007 10:51:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2252</guid>
		<description>thanks Sebastian, that was very helpful</description>
		<content:encoded><![CDATA[<p>thanks Sebastian, that was very helpful</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Wolfgarten</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2227</link>
		<dc:creator>Sebastian Wolfgarten</dc:creator>
		<pubDate>Thu, 11 Jan 2007 17:55:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2227</guid>
		<description>Okay, some stuff was stripped out from my previous posting...you basically need to wrap a FilesMatch-directive around the aforementioned "Header" settings...

Hope that helps!

Bye,
Seb</description>
		<content:encoded><![CDATA[<p>Okay, some stuff was stripped out from my previous posting&#8230;you basically need to wrap a FilesMatch-directive around the aforementioned &#8220;Header&#8221; settings&#8230;</p>
<p>Hope that helps!</p>
<p>Bye,<br />
Seb</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Wolfgarten</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2226</link>
		<dc:creator>Sebastian Wolfgarten</dc:creator>
		<pubDate>Thu, 11 Jan 2007 17:54:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2226</guid>
		<description>Hi,

well one way to prevent people from exploiting your customers is to add the following directive to Apache's httpd.conf:


Header unset Content-Disposition
Header add Content-Disposition "attachment; filename=document.pdf"


This will cause a save/open dialogue to pop up every time a user tries to download a .pdf file. As the "normal" Acrobat is not vulnerable (it's just the plugin), potentially attached malicious code will not be executed. If one wants to keep the original name of the .pdf file untouched, then one could use Apache's environment variables rather than setting it to "filename=document.pdf".

Bye,
Sebastian</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>well one way to prevent people from exploiting your customers is to add the following directive to Apache&#8217;s httpd.conf:</p>
<p>Header unset Content-Disposition<br />
Header add Content-Disposition &#8220;attachment; filename=document.pdf&#8221;</p>
<p>This will cause a save/open dialogue to pop up every time a user tries to download a .pdf file. As the &#8220;normal&#8221; Acrobat is not vulnerable (it&#8217;s just the plugin), potentially attached malicious code will not be executed. If one wants to keep the original name of the .pdf file untouched, then one could use Apache&#8217;s environment variables rather than setting it to &#8220;filename=document.pdf&#8221;.</p>
<p>Bye,<br />
Sebastian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matt</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2120</link>
		<dc:creator>matt</dc:creator>
		<pubDate>Tue, 09 Jan 2007 09:54:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2120</guid>
		<description>Nice Work.</description>
		<content:encoded><![CDATA[<p>Nice Work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marvin</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2076</link>
		<dc:creator>marvin</dc:creator>
		<pubDate>Mon, 08 Jan 2007 09:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2076</guid>
		<description>i tried that link, and it doesn't alert me with xss, but it prompts me to download that pdf file. Im using firefox 1.5.0.9 under ubuntu dapper</description>
		<content:encoded><![CDATA[<p>i tried that link, and it doesn&#8217;t alert me with xss, but it prompts me to download that pdf file. Im using firefox 1.5.0.9 under ubuntu dapper</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fearphage</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2056</link>
		<dc:creator>fearphage</dc:creator>
		<pubDate>Mon, 08 Jan 2007 01:52:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2056</guid>
		<description>This is already patched in Opera</description>
		<content:encoded><![CDATA[<p>This is already patched in Opera</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ingenieros&#8230; Â¿ lo lograremos ? &#187; Corrigiendo algunos fallos&#8230;</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2045</link>
		<dc:creator>Ingenieros&#8230; Â¿ lo lograremos ? &#187; Corrigiendo algunos fallos&#8230;</dc:creator>
		<pubDate>Sun, 07 Jan 2007 21:58:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2045</guid>
		<description>[...] - Ataque PDF: Todos vulnerables - Ataque PDF (II) : Y en tu ordenador tambiÃ©n - Universal PDF XSS After Party  CategorÃ­a: Sobre el blog &#124; [...]</description>
		<content:encoded><![CDATA[<p>[...] - Ataque PDF: Todos vulnerables - Ataque PDF (II) : Y en tu ordenador tambiÃ©n - Universal PDF XSS After Party  CategorÃ­a: Sobre el blog | [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2044</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Sun, 07 Jan 2007 20:28:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2044</guid>
		<description>&lt;blockquote&gt;Disable JavaScript or update to Acrobat 8.&lt;/blockquote&gt;
Or disable Acrobat plugin, or even delete it. For your main browser or for all browsers in the system. There are many suggestions.

Guys, as Google tell me, the are up to 317 000 000 sites in the Internet which have pdf files (and they all have this vulnerability). So every admin of every site and every user need to deal with this Universal PDF XSS.</description>
		<content:encoded><![CDATA[<blockquote><p>Disable JavaScript or update to Acrobat 8.</p></blockquote>
<p>Or disable Acrobat plugin, or even delete it. For your main browser or for all browsers in the system. There are many suggestions.</p>
<p>Guys, as Google tell me, the are up to 317 000 000 sites in the Internet which have pdf files (and they all have this vulnerability). So every admin of every site and every user need to deal with this Universal PDF XSS.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mighty Seek - Web Application Security Podcast and Blog &#187; Blog Archive &#187; Universal PDF XSS</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-2000</link>
		<dc:creator>Mighty Seek - Web Application Security Podcast and Blog &#187; Blog Archive &#187; Universal PDF XSS</dc:creator>
		<pubDate>Sun, 07 Jan 2007 02:17:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-2000</guid>
		<description>[...] Cross Site scripting attacks are getting even more dangerous these days, and exploitable in many new creative ways. I wil be discussing this issue in my next podcast, till then read up on it here or at ha.ckers.org [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross Site scripting attacks are getting even more dangerous these days, and exploitable in many new creative ways. I wil be discussing this issue in my next podcast, till then read up on it here or at ha.ckers.org [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MobileRead Networks - Unpatched Adobe Reader users in jeopardy</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-1992</link>
		<dc:creator>MobileRead Networks - Unpatched Adobe Reader users in jeopardy</dc:creator>
		<pubDate>Sat, 06 Jan 2007 22:00:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-1992</guid>
		<description>[...] Unpatched Adobe Reader users in jeopardy     Stefano Di Paola and Giorgio Fedon uncovered a serious cross-site scripting vulnerability that affects unpatched versions of the Adobe Reader plug-in which is used to view PDF files from within Web browsers. The vulnerability could allow an attacker to run malicious Javascript code on compromised systems. Security researchers advise us to update Adobe to at least V7.0.9 or V8.0.   Alternatively, you can disable the Adobe Reader browser plug-in (in Firefox within the Settings / Content / Filetypes menu). Or alternatively, use Foxit Reader instead.  Original paper discussing the vulnerability: link (careful, PDF!) Technical explanation of the vulnerability: link  [via CNet] [...]</description>
		<content:encoded><![CDATA[<p>[...] Unpatched Adobe Reader users in jeopardy     Stefano Di Paola and Giorgio Fedon uncovered a serious cross-site scripting vulnerability that affects unpatched versions of the Adobe Reader plug-in which is used to view PDF files from within Web browsers. The vulnerability could allow an attacker to run malicious Javascript code on compromised systems. Security researchers advise us to update Adobe to at least V7.0.9 or V8.0.   Alternatively, you can disable the Adobe Reader browser plug-in (in Firefox within the Settings / Content / Filetypes menu). Or alternatively, use Foxit Reader instead.  Original paper discussing the vulnerability: link (careful, PDF!) Technical explanation of the vulnerability: link  [via CNet] [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeremy Hannon</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-1954</link>
		<dc:creator>Jeremy Hannon</dc:creator>
		<pubDate>Fri, 05 Jan 2007 22:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-1954</guid>
		<description>Google may have changed their content-disposition to force the browser to treat it as a download rather than in-line.  That appears to mitigate the threat.</description>
		<content:encoded><![CDATA[<p>Google may have changed their content-disposition to force the browser to treat it as a download rather than in-line.  That appears to mitigate the threat.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Louise</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-1952</link>
		<dc:creator>Louise</dc:creator>
		<pubDate>Fri, 05 Jan 2007 22:02:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-1952</guid>
		<description>Everyone,

I got http://path/to/pdf/file.pdf#whatever_name_you_want=javascript:your_code_here to run in FF 1.5.0.7 on windows XP, but the file one did not run in that version</description>
		<content:encoded><![CDATA[<p>Everyone,</p>
<p>I got <a href="http://path/to/pdf/file.pdf#whatever_name_you_want=javascript:your_code_here" rel="nofollow">http://path/to/pdf/file.pdf#whatever_name_you_want=javascript:your_code_here</a> to run in FF 1.5.0.7 on windows XP, but the file one did not run in that version</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joel</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-1950</link>
		<dc:creator>Joel</dc:creator>
		<pubDate>Fri, 05 Jan 2007 21:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-1950</guid>
		<description>From what I found (http://secunia.com/advisories/23483/) they claim that this can affect both IE and FF depends on the specific version of browser and acrobat.


Although the alert did not work for me on FF (up to date 2.0.0.1) this did work.

file:///C:/Program%20Files/Adobe/Acrobat%206.0/Help/ENU/Pdfmark.pdf#a=javascript:window.location.href='http://www.google.com';

So my guess is the bug exists just because the plugin takes the window over, we don't get to see that window, however the bug does exist, and can be used.

Joel</description>
		<content:encoded><![CDATA[<p>From what I found (http://secunia.com/advisories/23483/) they claim that this can affect both IE and FF depends on the specific version of browser and acrobat.</p>
<p>Although the alert did not work for me on FF (up to date 2.0.0.1) this did work.</p>
<p>file:///C:/Program%20Files/Adobe/Acrobat%206.0/Help/ENU/Pdfmark.pdf#a=javascript:window.location.href=&#8217;http://www.google.com&#8217;;</p>
<p>So my guess is the bug exists just because the plugin takes the window over, we don&#8217;t get to see that window, however the bug does exist, and can be used.</p>
<p>Joel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Klir</title>
		<link>/blog/universal-pdf-xss-after-party/#comment-1939</link>
		<dc:creator>Klir</dc:creator>
		<pubDate>Fri, 05 Jan 2007 16:34:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/universal-pdf-xss-after-party#comment-1939</guid>
		<description>Itâ€™s not occurs on IE 7, IE6 SP2 FF 2.0.2 , 1.5.0.9 on windows XP ...
If a user still didnâ€™t understand that he needs to upgrade to the latest patch than maybe he deserve to be hackedâ€¦</description>
		<content:encoded><![CDATA[<p>Itâ€™s not occurs on IE 7, IE6 SP2 FF 2.0.2 , 1.5.0.9 on windows XP &#8230;<br />
If a user still didnâ€™t understand that he needs to upgrade to the latest patch than maybe he deserve to be hackedâ€¦</p>
]]></content:encoded>
	</item>
</channel>
</rss>
