<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: PDF, Let Me Count the Ways&#8230;</title>
	<atom:link href="http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Security PDF-related links in 2010: analyses and tools</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-45080</link>
		<dc:creator><![CDATA[Security PDF-related links in 2010: analyses and tools]]></dc:creator>
		<pubDate>Wed, 10 Aug 2011 01:25:34 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-45080</guid>
		<description><![CDATA[[...] lot of analyses from Contagiodump blog 2011 PDF – Vulnerabilities, Exploits and Malwares 2011  PDF, Let Me Count the Ways 2011 Analysing a Malicious PDF Document 2010 The Rise of PDF [...]]]></description>
		<content:encoded><![CDATA[<p>[...] lot of analyses from Contagiodump blog 2011 PDF – Vulnerabilities, Exploits and Malwares 2011  PDF, Let Me Count the Ways 2011 Analysing a Malicious PDF Document 2010 The Rise of PDF [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Secur-IT</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-41370</link>
		<dc:creator><![CDATA[Secur-IT]]></dc:creator>
		<pubDate>Thu, 06 Jan 2011 13:25:49 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-41370</guid>
		<description><![CDATA[[...] peut être intéressant de noter que pdfid supporte l&#8217;obfuscation des noms : que le nom de l&#8217;objet soit en ASCII, ANSI, hexadécimal ou autre type [...]]]></description>
		<content:encoded><![CDATA[<p>[...] peut être intéressant de noter que pdfid supporte l&#8217;obfuscation des noms : que le nom de l&#8217;objet soit en ASCII, ANSI, hexadécimal ou autre type [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Analysing a Malicious PDF Document</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-40465</link>
		<dc:creator><![CDATA[Analysing a Malicious PDF Document]]></dc:creator>
		<pubDate>Sat, 06 Nov 2010 12:08:53 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-40465</guid>
		<description><![CDATA[[...] Stevens has a list of malicious PDF obfuscation methods here, for those interested in the [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Stevens has a list of malicious PDF obfuscation methods here, for those interested in the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-39526</link>
		<dc:creator><![CDATA[Doug]]></dc:creator>
		<pubDate>Sat, 14 Aug 2010 18:53:22 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-39526</guid>
		<description><![CDATA[Any chance you have a series of benign PDF&#039;s that demonstrate the different types of vulnerabilities you&#039;ve seen malware use (or for that mater even malware infested PDF&#039;s).

Like Ariel, I&#039;m writing something to hopefully help detect this stuff. In my case I&#039;m writing it in PHP to be used with a website that is going to let users upload PDF&#039;s. 

Thanks,
Doug]]></description>
		<content:encoded><![CDATA[<p>Any chance you have a series of benign PDF&#8217;s that demonstrate the different types of vulnerabilities you&#8217;ve seen malware use (or for that mater even malware infested PDF&#8217;s).</p>
<p>Like Ariel, I&#8217;m writing something to hopefully help detect this stuff. In my case I&#8217;m writing it in PHP to be used with a website that is going to let users upload PDF&#8217;s. </p>
<p>Thanks,<br />
Doug</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Les outils d&#8217;analyse de PDF &#171; Elevenses blog</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-38506</link>
		<dc:creator><![CDATA[Les outils d&#8217;analyse de PDF &#171; Elevenses blog]]></dc:creator>
		<pubDate>Mon, 10 May 2010 16:26:10 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-38506</guid>
		<description><![CDATA[[...] est intéressant de noter que pdfid supporte l&#039;obfuscation des noms : que le nom de l&#039;objet soit en ASCII, ANSI, hexadécimal ou autre type d&#039;encodage, pdfid [...]]]></description>
		<content:encoded><![CDATA[<p>[...] est intéressant de noter que pdfid supporte l&#039;obfuscation des noms : que le nom de l&#039;objet soit en ASCII, ANSI, hexadécimal ou autre type d&#039;encodage, pdfid [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chirashi Security &#187; Malicious PDF files and embedding</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-35350</link>
		<dc:creator><![CDATA[Chirashi Security &#187; Malicious PDF files and embedding]]></dc:creator>
		<pubDate>Wed, 15 Jul 2009 05:35:05 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-35350</guid>
		<description><![CDATA[[...] another object to a PDF file.  So I tried to add a URI with OpenAction similar to Didier in this post.  I opened the new file in Preview; absolutely nothing.  Knowing that I had to be more thorough, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] another object to a PDF file.  So I tried to add a URI with OpenAction similar to Didier in this post.  I opened the new file in Preview; absolutely nothing.  Knowing that I had to be more thorough, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abusing PDFs &#171; Security For All</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-35309</link>
		<dc:creator><![CDATA[Abusing PDFs &#171; Security For All]]></dc:creator>
		<pubDate>Wed, 08 Jul 2009 21:03:38 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-35309</guid>
		<description><![CDATA[[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Embedding and Hiding Files in PDF Documents - Opsec</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-35259</link>
		<dc:creator><![CDATA[Embedding and Hiding Files in PDF Documents - Opsec]]></dc:creator>
		<pubDate>Wed, 01 Jul 2009 17:22:39 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-35259</guid>
		<description><![CDATA[[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Embedding and Hiding Files in PDF Documents &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-35252</link>
		<dc:creator><![CDATA[Embedding and Hiding Files in PDF Documents &#171; Didier Stevens]]></dc:creator>
		<pubDate>Wed, 01 Jul 2009 06:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-35252</guid>
		<description><![CDATA[[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]]]></description>
		<content:encoded><![CDATA[<p>[...] if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Updates: bpmtk and Hakin9; PDF and Metasploit &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/04/29/pdf-let-me-count-the-ways/#comment-33836</link>
		<dc:creator><![CDATA[Updates: bpmtk and Hakin9; PDF and Metasploit &#171; Didier Stevens]]></dc:creator>
		<pubDate>Tue, 09 Dec 2008 21:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=369#comment-33836</guid>
		<description><![CDATA[[...] On the PDF front: I&#8217;ve produced my first Ruby code ;-). I worked together with MC from Metasploit to optimize the PDF generation code in this util.printf exploit module. It uses some obfuscation techniques I described 8 months ago. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] On the PDF front: I&#8217;ve produced my first Ruby code <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> . I worked together with MC from Metasploit to optimize the PDF generation code in this util.printf exploit module. It uses some obfuscation techniques I described 8 months ago. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

