Didier Stevens

Thursday 21 January 2010

Quickpost: PDF Header %!PS-Adobe-N.n PDF-M.m

Filed under: My Software,PDF,Quickpost — Didier Stevens @ 11:21

@Feliam has an interesting PDF library to create PDF files with an unconventional header (the generated document doesn’t start with %PDF-…, but %PDF appears somewhere in the first 1024 bytes of the document). As this trick is likely to be taken over by malware authors, I updated PDFiD to support this.

The PDF reference document also mentions %!PS-Adobe-N.n PDF-M.m as a valid header, however, the PDF documents I and @Feliam generated with this header are not rendered by Adobe Reader (neither Foxit or Sumatra PDF).

I was told Adobe did support this header in older versions. My tests show Adobe Reader version 3, 4, 5 and 6 will render PDF documents with header %!PS-Adobe-N.n PDF-M.m. Versions 7, 8 and 9 will not. Therefor I decided not to include support for this header to PDFiD.

pdf-parser doesn’t test the header, it analyzes PDF documents regardless of the header.

4 Comments »

  1. That’s the bypass I reported to kaspersky,f-secure,ca etc etc

    Comment by Thierry Zoller — Friday 22 January 2010 @ 15:31

  2. Addendum: http://blog.zoller.lu/2009/05/advisory-kaspersky-generic-pdf-evasion.html

    Comment by Thierry Zoller — Friday 22 January 2010 @ 15:44

  3. @Thierry Zoller Nice!

    Comment by Didier Stevens — Friday 22 January 2010 @ 16:25

  4. [...] Quickpost: PDF Header %!PS-Adobe-N.n PDF-M.m – didierstevens.com A curious PDF header is spotted which might be exploited by malware authors. [...]

    Pingback by | Infosec Events — Monday 25 January 2010 @ 7:14


RSS feed for comments on this post. TrackBack URI

Leave a Reply (comments are moderated)

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

The Rubric Theme. Blog at WordPress.com.

Follow

Get every new post delivered to your Inbox.

Join 234 other followers

%d bloggers like this: