<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: PDF Strikes Back</title>
	<atom:link href="http://www.gnucitizen.org/projects/pdf-strikes-back/feed/" rel="self" type="application/rss+xml" />
	<link>/projects/pdf-strikes-back/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 20:09:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: BoletÃ­n 00089 - 15/03/2007 at Aullando con el Lobo (W.O.L.F.)</title>
		<link>/projects/pdf-strikes-back/#comment-51873</link>
		<dc:creator>BoletÃ­n 00089 - 15/03/2007 at Aullando con el Lobo (W.O.L.F.)</dc:creator>
		<pubDate>Sun, 23 Sep 2007 21:12:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-51873</guid>
		<description>[...] PDF Strikes Back http://www.gnucitizen.org/projects/pdf-strikes-back/ [...]</description>
		<content:encoded><![CDATA[<p>[...] PDF Strikes Back <a href="http://www.gnucitizen.org/projects/pdf-strikes-back/" rel="nofollow">http://www.gnucitizen.org/projects/pdf-strikes-back/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>/projects/pdf-strikes-back/#comment-22781</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Sun, 20 May 2007 11:52:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-22781</guid>
		<description>I'm sorry, but can you tell the difference between UXSS and XSS ? I mean, when do I have to call it XSS and when UXSS ?
Thanks !</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry, but can you tell the difference between UXSS and XSS ? I mean, when do I have to call it XSS and when UXSS ?<br />
Thanks !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arvutikaitse &#187; Blog Archive &#187; PDF kui uks sinu arvutisse</title>
		<link>/projects/pdf-strikes-back/#comment-11229</link>
		<dc:creator>Arvutikaitse &#187; Blog Archive &#187; PDF kui uks sinu arvutisse</dc:creator>
		<pubDate>Fri, 30 Mar 2007 06:32:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-11229</guid>
		<description>[...] Kasutajainfo ja kasutusinfo levitamine ei paista olevat vÃ¤ga suur probleem, kuid Adobe tooted vÃµimaldavad avada (ja seega edastada) ka sinu arvutis olevaid faile (CVE-2007-1199, SA24408, pdp). [...]</description>
		<content:encoded><![CDATA[<p>[...] Kasutajainfo ja kasutusinfo levitamine ei paista olevat vÃ¤ga suur probleem, kuid Adobe tooted vÃµimaldavad avada (ja seega edastada) ka sinu arvutis olevaid faile (CVE-2007-1199, SA24408, pdp). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; PDF and History Hacks</title>
		<link>/projects/pdf-strikes-back/#comment-5729</link>
		<dc:creator>GNUCITIZEN &#187; PDF and History Hacks</dc:creator>
		<pubDate>Fri, 02 Mar 2007 15:42:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5729</guid>
		<description>[...] First of all, let&#8217;s see what is happening on the client-side web hacking front-line. It is possible to steal the browser history by using an approach quite different from what Jeremiah Grossman came up with last year. I am making use of script tags together with about:cache protocol leeks. This works on Firefox 2.0.0.2 which means that if this is what you are using right now, you are most definitely vulnerable. [...]</description>
		<content:encoded><![CDATA[<p>[...] First of all, let&#8217;s see what is happening on the client-side web hacking front-line. It is possible to steal the browser history by using an approach quite different from what Jeremiah Grossman came up with last year. I am making use of script tags together with about:cache protocol leeks. This works on Firefox 2.0.0.2 which means that if this is what you are using right now, you are most definitely vulnerable. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/projects/pdf-strikes-back/#comment-5656</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 01 Mar 2007 20:57:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5656</guid>
		<description>This is weird! Thanks.</description>
		<content:encoded><![CDATA[<p>This is weird! Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MustLive</title>
		<link>/projects/pdf-strikes-back/#comment-5652</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Thu, 01 Mar 2007 19:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5652</guid>
		<description>&lt;blockquote&gt;The following number of POCs (Proof of Concept) work on Adobe Reader 8.0. Other versions might be vulnerable too.&lt;/blockquote&gt;

It is also work in my Acrobat 6.0 (but only tow tests). Pdp, not all PoCs worked in my case, just first two.

poc01.pdf - work (open file&#58;///C:/)
poc02.pdf - work (show the file path)

Other three: poc03-ie.pdf, poc03-ff.pdf and poc03-op.pdf didn't work. Because my system (Win XP SP2) didn't like file names with # character. So that PoCs didn't work in my Mozilla, Firefox and IE.</description>
		<content:encoded><![CDATA[<blockquote><p>The following number of POCs (Proof of Concept) work on Adobe Reader 8.0. Other versions might be vulnerable too.</p></blockquote>
<p>It is also work in my Acrobat 6.0 (but only tow tests). Pdp, not all PoCs worked in my case, just first two.</p>
<p>poc01.pdf - work (open file&#58;///C:/)<br />
poc02.pdf - work (show the file path)</p>
<p>Other three: poc03-ie.pdf, poc03-ff.pdf and poc03-op.pdf didn&#8217;t work. Because my system (Win XP SP2) didn&#8217;t like file names with # character. So that PoCs didn&#8217;t work in my Mozilla, Firefox and IE.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/projects/pdf-strikes-back/#comment-5638</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 01 Mar 2007 12:18:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5638</guid>
		<description>Wokker, it is a new issue. However, I do use the Universal PDF XSS to better explain the risk. Wait for my blog entry which will detail this finding.</description>
		<content:encoded><![CDATA[<p>Wokker, it is a new issue. However, I do use the Universal PDF XSS to better explain the risk. Wait for my blog entry which will detail this finding.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wokker</title>
		<link>/projects/pdf-strikes-back/#comment-5635</link>
		<dc:creator>Wokker</dc:creator>
		<pubDate>Thu, 01 Mar 2007 11:12:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5635</guid>
		<description>Is this a new issue or is this the same issue that you reported in http://www.gnucitizen.org/blog/danger-danger-danger?
Only with some new Poc's ?</description>
		<content:encoded><![CDATA[<p>Is this a new issue or is this the same issue that you reported in <a href="http://www.gnucitizen.org/blog/danger-danger-danger?" rel="nofollow">http://www.gnucitizen.org/blog/danger-danger-danger?</a><br />
Only with some new Poc&#8217;s ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The show must go on at Disenchant&#8217;s Blog</title>
		<link>/projects/pdf-strikes-back/#comment-5630</link>
		<dc:creator>The show must go on at Disenchant&#8217;s Blog</dc:creator>
		<pubDate>Thu, 01 Mar 2007 08:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5630</guid>
		<description>[...] pdp wrote an interesting blog posting today about his research on the well known so called PDF UXSS vulnerability. Because pdp did a good job on his posting, I just want to quote a part of it: [...]</description>
		<content:encoded><![CDATA[<p>[...] pdp wrote an interesting blog posting today about his research on the well known so called PDF UXSS vulnerability. Because pdp did a good job on his posting, I just want to quote a part of it: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kishor</title>
		<link>/projects/pdf-strikes-back/#comment-5625</link>
		<dc:creator>Kishor</dc:creator>
		<pubDate>Thu, 01 Mar 2007 05:13:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5625</guid>
		<description>Scary!

Because it reveals my user name which is very important in order to guess some of the vulnerable htmls that might be present in my temp directory. These HTMLs can be the exploited further may be using http://www.gnucitizen.org/projects/pdf-strikes-back/poc01.pdf.

c:\docume~1\USERNAME\locals~1\temp\poc02-2.pdf</description>
		<content:encoded><![CDATA[<p>Scary!</p>
<p>Because it reveals my user name which is very important in order to guess some of the vulnerable htmls that might be present in my temp directory. These HTMLs can be the exploited further may be using <a href="http://www.gnucitizen.org/projects/pdf-strikes-back/poc01.pdf" rel="nofollow">http://www.gnucitizen.org/projects/pdf-strikes-back/poc01.pdf</a>.</p>
<p>c:\docume~1\USERNAME\locals~1\temp\poc02-2.pdf</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: javier</title>
		<link>/projects/pdf-strikes-back/#comment-5597</link>
		<dc:creator>javier</dc:creator>
		<pubDate>Wed, 28 Feb 2007 22:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5597</guid>
		<description>FYI. Nothing happens using Foxit reader on win XP2. So opening documents this way should be considered a little more secure.</description>
		<content:encoded><![CDATA[<p>FYI. Nothing happens using Foxit reader on win XP2. So opening documents this way should be considered a little more secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pagvac</title>
		<link>/projects/pdf-strikes-back/#comment-5564</link>
		<dc:creator>pagvac</dc:creator>
		<pubDate>Wed, 28 Feb 2007 13:38:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/pdf-strikes-back#comment-5564</guid>
		<description>Tried poc01 on Adobe Acrobat Reader 8.0 (Windows XP SP2) and it &lt;strong&gt;does&lt;/strong&gt; open 'C:' using the default web browser.

It's interesting that Adobe Acrobat Reader 4.0 does open 'C:' using Windows' 'explorer.exe' as opposed to the default web browser.</description>
		<content:encoded><![CDATA[<p>Tried poc01 on Adobe Acrobat Reader 8.0 (Windows XP SP2) and it <strong>does</strong> open &#8216;C:&#8217; using the default web browser.</p>
<p>It&#8217;s interesting that Adobe Acrobat Reader 4.0 does open &#8216;C:&#8217; using Windows&#8217; &#8216;explorer.exe&#8217; as opposed to the default web browser.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
