<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: PDF Info Stealer PoC</title>
	<atom:link href="http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Wed, 08 Feb 2012 19:23:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: All PDFs are not created Equal &#171; The Journeyler</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-42070</link>
		<dc:creator><![CDATA[All PDFs are not created Equal &#171; The Journeyler]]></dc:creator>
		<pubDate>Tue, 15 Mar 2011 21:12:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-42070</guid>
		<description><![CDATA[[...] of todays major security loopholes is malformed file types, i.e. PDFs that are not really PDFs or PDFs with something malicious attached or [...]]]></description>
		<content:encoded><![CDATA[<p>[...] of todays major security loopholes is malformed file types, i.e. PDFs that are not really PDFs or PDFs with something malicious attached or [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bruno Kerouanton &#187; Failles PDF&#8230;</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-38033</link>
		<dc:creator><![CDATA[Bruno Kerouanton &#187; Failles PDF&#8230;]]></dc:creator>
		<pubDate>Thu, 01 Apr 2010 06:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-38033</guid>
		<description><![CDATA[[...] c&#8217;est quand Didier Stevens y intègre un programme pour voler des informations sensibles. Ce billet montre comment un &#171;&#160;simple&#160;&#187; fichier PDF est capable de chercher puis de transmettre [...]]]></description>
		<content:encoded><![CDATA[<p>[...] c&#8217;est quand Didier Stevens y intègre un programme pour voler des informations sensibles. Ce billet montre comment un &laquo;&nbsp;simple&nbsp;&raquo; fichier PDF est capable de chercher puis de transmettre [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GreenSquirrel</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37862</link>
		<dc:creator><![CDATA[GreenSquirrel]]></dc:creator>
		<pubDate>Mon, 22 Mar 2010 19:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37862</guid>
		<description><![CDATA[Very interesting and somewhat disturbing for those tasked with preventing data leakage. Thank you for posting this.

(Its a shame people seem to have fixated on the mechanism you have used, PDF, rather than the more worrying concept it demonstrates).

At the moment it does seem like encryption is the only real mitigtion against this - assuming it can workout unexpected file names.]]></description>
		<content:encoded><![CDATA[<p>Very interesting and somewhat disturbing for those tasked with preventing data leakage. Thank you for posting this.</p>
<p>(Its a shame people seem to have fixated on the mechanism you have used, PDF, rather than the more worrying concept it demonstrates).</p>
<p>At the moment it does seem like encryption is the only real mitigtion against this &#8211; assuming it can workout unexpected file names.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37847</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 17 Mar 2010 18:58:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37847</guid>
		<description><![CDATA[@Irgendwer No, I just call SHGetFolderPath with CSIDL_PERSONAL to get the absolute path to My Documents.]]></description>
		<content:encoded><![CDATA[<p>@Irgendwer No, I just call SHGetFolderPath with CSIDL_PERSONAL to get the absolute path to My Documents.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Irgendwer</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37846</link>
		<dc:creator><![CDATA[Irgendwer]]></dc:creator>
		<pubDate>Wed, 17 Mar 2010 18:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37846</guid>
		<description><![CDATA[Interesting technique... 
Is there a string in the dll looking for &quot;My Documents&quot;?]]></description>
		<content:encoded><![CDATA[<p>Interesting technique&#8230;<br />
Is there a string in the dll looking for &#8220;My Documents&#8221;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37833</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Sun, 14 Mar 2010 21:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37833</guid>
		<description><![CDATA[No, even if I call this a PoC, the payload is still an info stealer, I&#039;m not publishing this. And the DLL can be adapted to collect several files.]]></description>
		<content:encoded><![CDATA[<p>No, even if I call this a PoC, the payload is still an info stealer, I&#8217;m not publishing this. And the DLL can be adapted to collect several files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nazz</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37829</link>
		<dc:creator><![CDATA[Nazz]]></dc:creator>
		<pubDate>Sat, 13 Mar 2010 20:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37829</guid>
		<description><![CDATA[Any way of releasing the payload itself, So it loads a certain dll into the memory to search for important files in which you gave it to search e.g. passwords.xls, secret.txt, ftp.txt could it search for more than one file or do you have to edit shellcode each time?]]></description>
		<content:encoded><![CDATA[<p>Any way of releasing the payload itself, So it loads a certain dll into the memory to search for important files in which you gave it to search e.g. passwords.xls, secret.txt, <a href="http://ftp.txt" rel="nofollow">http://ftp.txt</a> could it search for more than one file or do you have to edit shellcode each time?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frisky Solitaire &#8211; Another Info Stealer &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37802</link>
		<dc:creator><![CDATA[Frisky Solitaire &#8211; Another Info Stealer &#171; Didier Stevens]]></dc:creator>
		<pubDate>Tue, 09 Mar 2010 00:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37802</guid>
		<description><![CDATA[[...] people have asked me about de details of the vulnerability I exploited in my PDF Info Stealer PoC. But that&#8217;s not important. It&#8217;s not about the exploit, it&#8217;s about the payload: [...]]]></description>
		<content:encoded><![CDATA[<p>[...] people have asked me about de details of the vulnerability I exploited in my PDF Info Stealer PoC. But that&#8217;s not important. It&#8217;s not about the exploit, it&#8217;s about the payload: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37801</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 08 Mar 2010 17:29:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37801</guid>
		<description><![CDATA[@Christoph Schmees It&#039;s not about the vulnerability or the exploit, but about the payload. Like I wrote: I can do this with Office vulnerabilities too, or even without any vulnerability, just social-engineering you to open a spreadsheet and execute macros. I use an old Adobe Reader vulnerability (util.printf) to execute the info stealer payload, but like I said, that&#039;s just because it&#039;s easy for me to do so.]]></description>
		<content:encoded><![CDATA[<p>@Christoph Schmees It&#8217;s not about the vulnerability or the exploit, but about the payload. Like I wrote: I can do this with Office vulnerabilities too, or even without any vulnerability, just social-engineering you to open a spreadsheet and execute macros. I use an old Adobe Reader vulnerability (util.printf) to execute the info stealer payload, but like I said, that&#8217;s just because it&#8217;s easy for me to do so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christoph Schmees</title>
		<link>http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/#comment-37800</link>
		<dc:creator><![CDATA[Christoph Schmees]]></dc:creator>
		<pubDate>Mon, 08 Mar 2010 16:29:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2046#comment-37800</guid>
		<description><![CDATA[The exploit targets *Adobe* reader, right? What about other free PRF readers such as Foxit or PDF-XChange? Are they immune? If so, it should be pointed out that this is about an *Adobe* weakness, not a general PDF weaknes!]]></description>
		<content:encoded><![CDATA[<p>The exploit targets *Adobe* reader, right? What about other free PRF readers such as Foxit or PDF-XChange? Are they immune? If so, it should be pointed out that this is about an *Adobe* weakness, not a general PDF weaknes!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

