<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Preventing Applications From Starting (Malicious) Applications</title>
	<atom:link href="http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Geraldine</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-48750</link>
		<dc:creator><![CDATA[Geraldine]]></dc:creator>
		<pubDate>Wed, 21 Dec 2011 15:53:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-48750</guid>
		<description><![CDATA[Thanks for that! It\&#039;s just the answer I neeedd.]]></description>
		<content:encoded><![CDATA[<p>Thanks for that! It\&#8217;s just the answer I neeedd.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Triflex Enterprise &#124; PDFs Exploitable?!? I’m shocked…</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-38329</link>
		<dc:creator><![CDATA[Triflex Enterprise &#124; PDFs Exploitable?!? I’m shocked…]]></dc:creator>
		<pubDate>Thu, 22 Apr 2010 05:20:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-38329</guid>
		<description><![CDATA[[...] PDF readers could disable the functionality completely (perhaps using Didier Stevens’ developed method) or bide their time, waiting on [...]]]></description>
		<content:encoded><![CDATA[<p>[...] PDF readers could disable the functionality completely (perhaps using Didier Stevens’ developed method) or bide their time, waiting on [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacker finds a way to exploit PDF files &#124; The PC Report</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-38026</link>
		<dc:creator><![CDATA[Hacker finds a way to exploit PDF files &#124; The PC Report]]></dc:creator>
		<pubDate>Thu, 01 Apr 2010 03:35:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-38026</guid>
		<description><![CDATA[[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Escape from PDF</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-38007</link>
		<dc:creator><![CDATA[Escape from PDF]]></dc:creator>
		<pubDate>Wed, 31 Mar 2010 19:53:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-38007</guid>
		<description><![CDATA[[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-37972</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 31 Mar 2010 11:19:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-37972</guid>
		<description><![CDATA[@Reader because that will not help you exploits that download and execute malware.]]></description>
		<content:encoded><![CDATA[<p>@Reader because that will not help you exploits that download and execute malware.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reader</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-37970</link>
		<dc:creator><![CDATA[Reader]]></dc:creator>
		<pubDate>Wed, 31 Mar 2010 11:11:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-37970</guid>
		<description><![CDATA[Why not just disable non-PDF file attachments in Trust Manager settings of Adobe Reader?

Prefs -&gt; Trust Manader -&gt; PDF File Attachments -&gt; [ ] Allow opening...]]></description>
		<content:encoded><![CDATA[<p>Why not just disable non-PDF file attachments in Trust Manager settings of Adobe Reader?</p>
<p>Prefs -&gt; Trust Manader -&gt; PDF File Attachments -&gt; [ ] Allow opening&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Escape From PDF (hack exposed) &#124; Cell-Systems</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-37937</link>
		<dc:creator><![CDATA[Escape From PDF (hack exposed) &#124; Cell-Systems]]></dc:creator>
		<pubDate>Tue, 30 Mar 2010 17:21:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-37937</guid>
		<description><![CDATA[[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Escape From PDF &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-37892</link>
		<dc:creator><![CDATA[Escape From PDF &#171; Didier Stevens]]></dc:creator>
		<pubDate>Mon, 29 Mar 2010 19:46:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-37892</guid>
		<description><![CDATA[[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]]]></description>
		<content:encoded><![CDATA[<p>[...] should they consider that the protection offered by the warning dialog is not sufficient. BTW, preventing Adobe Reader from creating new processes blocks this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-35901</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 12 Oct 2009 21:50:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-35901</guid>
		<description><![CDATA[&gt; Otherwise, it’s only ’secure’ as far as the ‘attackers’ don’t bother to work around it.
That&#039;s always the case. If I have local admin rights, I can also work around the protection you set up in the kernel. To avoid that, you need a TPM and a chain of trust. Until someone breaks the weakest link in that chain...
It&#039;s an arms race.

And another way to bypass this altogether is just not to create a new process...
Use shellcode: http://blog.didierstevens.com/2008/10/23/excel-exercises-in-style/
Or a DLL: http://blog.didierstevens.com/2008/06/05/bpmtk-how-about-srp-whitelists/
]]></description>
		<content:encoded><![CDATA[<p>&gt; Otherwise, it’s only ’secure’ as far as the ‘attackers’ don’t bother to work around it.<br />
That&#8217;s always the case. If I have local admin rights, I can also work around the protection you set up in the kernel. To avoid that, you need a TPM and a chain of trust. Until someone breaks the weakest link in that chain&#8230;<br />
It&#8217;s an arms race.</p>
<p>And another way to bypass this altogether is just not to create a new process&#8230;<br />
Use shellcode: <a href="http://blog.didierstevens.com/2008/10/23/excel-exercises-in-style/" rel="nofollow">http://blog.didierstevens.com/2008/10/23/excel-exercises-in-style/</a><br />
Or a DLL: <a href="http://blog.didierstevens.com/2008/06/05/bpmtk-how-about-srp-whitelists/" rel="nofollow">http://blog.didierstevens.com/2008/06/05/bpmtk-how-about-srp-whitelists/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.didierstevens.com/2009/10/05/preventing-applications-from-starting-malicious-applications/#comment-35899</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Mon, 12 Oct 2009 21:35:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1786#comment-35899</guid>
		<description><![CDATA[Process creation disabling should be done by the kernel in order to be really secure. Usermode could do something like disabling a token, but I don&#039;t think that hooking can provide real security.
The point in blocking this is that it is going to run insecure, malicious, untrusted code. Thus, we should consider that the author knows the way we&#039;re going to block its code. The protection should still work even on this case. Otherwise, it&#039;s only &#039;secure&#039; as far as the &#039;attackers&#039; don&#039;t bother to work around it.]]></description>
		<content:encoded><![CDATA[<p>Process creation disabling should be done by the kernel in order to be really secure. Usermode could do something like disabling a token, but I don&#8217;t think that hooking can provide real security.<br />
The point in blocking this is that it is going to run insecure, malicious, untrusted code. Thus, we should consider that the author knows the way we&#8217;re going to block its code. The protection should still work even on this case. Otherwise, it&#8217;s only &#8216;secure&#8217; as far as the &#8216;attackers&#8217; don&#8217;t bother to work around it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

