Re: xpdf and acrobat reader hole
Sam Halliday <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
James Iwanek wrote: > Jochen Schroeder wrote: > > There is a whole in acrobat reader and xpdf which let's you execute > > any shell command from within a pdf-dokument. Nice thing if you > > embed rm -rf$HOME/* within an pdf-file. Am still not quite sure if > > this really is a hole or considered a feature ;-). Anyways here's > > the relevant link: > > http://lists.netsys.com/pipermail/full-disclosure/2003-June/010397.html > any fool knows you have a more robust hack if you were to replace > monkey with $USER ;-) `rm -rf $HOME/$USER` can't see that doing much :-/ (e.g. expanded=`rm -rf /home/samuel/samuel`) however, a REAL fool would use the opportunity to plant a backdoor or mail a secret GPG key back home... the simplicity of this exploit is quite scary, i imagine that most applications/formats have similar issues; especially with everything trying so hard to interoperate on a point-and-click basis. i wonder if large archives like arXiv.org are going to parse for this kind of thing? they generate PDF files on demand (with some level of caching) from the source .tex files. however, someone actually using this kind of exploit with their name attached to it is enough to lose them a career in research, but it is scary that such an exploit is possible to begin with... Sam... thinking about moving this to lfs-chat -- Trespassers will be shot. Survivors will be SHOT AGAIN!
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE+7mn13qTuwoWzAjMRAu26AJoDpl0IBOZGTPLZayvdWoWJV2U6OACgqhgC el3R8K3jClJ0Ji79jr6bLV8= =NSVI -----END PGP SIGNATURE-----