<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Quickpost: No Escape From PDF</title>
	<atom:link href="http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: escape from PDF &#124; Linux-backtrack.com</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-41882</link>
		<dc:creator><![CDATA[escape from PDF &#124; Linux-backtrack.com]]></dc:creator>
		<pubDate>Sat, 19 Feb 2011 21:21:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-41882</guid>
		<description><![CDATA[[...] droits de l&#8217;utilisateur [5]. Cette vulnérabilité a été en partie patchée en juin 2010 [6], puis un moyen de contourner le patch a été publié en juillet [7]. Un nouveau patch a été [...]]]></description>
		<content:encoded><![CDATA[<p>[...] droits de l&#8217;utilisateur [5]. Cette vulnérabilité a été en partie patchée en juin 2010 [6], puis un moyen de contourner le patch a été publié en juillet [7]. Un nouveau patch a été [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quickpost: Preventing the /Launch Action &#8220;cmd.exe&#8221; Bypass &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39038</link>
		<dc:creator><![CDATA[Quickpost: Preventing the /Launch Action &#8220;cmd.exe&#8221; Bypass &#171; Didier Stevens]]></dc:creator>
		<pubDate>Sun, 04 Jul 2010 21:20:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39038</guid>
		<description><![CDATA[[...] Stevens @ 21:20   Adobe has released a new Adobe Reader version that contains functionality to block my /Launch action PoC, but Bkis found a bypass: just put double quotes around cmd.exe, like this:  [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Stevens @ 21:20   Adobe has released a new Adobe Reader version that contains functionality to block my /Launch action PoC, but Bkis found a bypass: just put double quotes around cmd.exe, like this:  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adobe fix still allows “Escape from PDF” &#124; MEDOIX</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39022</link>
		<dc:creator><![CDATA[Adobe fix still allows “Escape from PDF” &#124; MEDOIX]]></dc:creator>
		<pubDate>Thu, 01 Jul 2010 06:02:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39022</guid>
		<description><![CDATA[[...] has taken Adobe three months to release the patch. On the blog entry, Didier confirms that Adobe has completely fixed the flaw. However the patch turns out to be [...]]]></description>
		<content:encoded><![CDATA[<p>[...] has taken Adobe three months to release the patch. On the blog entry, Didier confirms that Adobe has completely fixed the flaw. However the patch turns out to be [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Royal</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39020</link>
		<dc:creator><![CDATA[Royal]]></dc:creator>
		<pubDate>Thu, 01 Jul 2010 04:45:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39020</guid>
		<description><![CDATA[Didier, Please escape form PDF
http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/]]></description>
		<content:encoded><![CDATA[<p>Didier, Please escape form PDF<br />
<a href="http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/" rel="nofollow">http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39019</link>
		<dc:creator><![CDATA[Paul]]></dc:creator>
		<pubDate>Thu, 01 Jul 2010 01:01:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39019</guid>
		<description><![CDATA[Did you see this reference to an easy bypass of the &#039;fix&#039;?  It appears in comments to ISC&#039;s story on the patch.
http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/]]></description>
		<content:encoded><![CDATA[<p>Did you see this reference to an easy bypass of the &#8216;fix&#8217;?  It appears in comments to ISC&#8217;s story on the patch.<br />
<a href="http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/" rel="nofollow">http://blog.bkis.com/en/adobe-fix-still-allows-escape-from-pdf/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wim</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39017</link>
		<dc:creator><![CDATA[Wim]]></dc:creator>
		<pubDate>Wed, 30 Jun 2010 21:17:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39017</guid>
		<description><![CDATA[I know this is a lazy comment but can you confirm that either the /Launch command can not be enabled or that if it can be (through registry setting?), the message box is still mandatory and can not be modified ?]]></description>
		<content:encoded><![CDATA[<p>I know this is a lazy comment but can you confirm that either the /Launch command can not be enabled or that if it can be (through registry setting?), the message box is still mandatory and can not be modified ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39013</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Wed, 30 Jun 2010 16:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39013</guid>
		<description><![CDATA[@Nobody Will disclose this at Brucon.org]]></description>
		<content:encoded><![CDATA[<p>@Nobody Will disclose this at Brucon.org</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zhane</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39010</link>
		<dc:creator><![CDATA[zhane]]></dc:creator>
		<pubDate>Wed, 30 Jun 2010 14:07:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39010</guid>
		<description><![CDATA[time to come up with some other attacks :)]]></description>
		<content:encoded><![CDATA[<p>time to come up with some other attacks <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adobe Reader and Acrobat updates close 17 critical holes</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39009</link>
		<dc:creator><![CDATA[Adobe Reader and Acrobat updates close 17 critical holes]]></dc:creator>
		<pubDate>Wed, 30 Jun 2010 12:58:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39009</guid>
		<description><![CDATA[[...] applications&quot; feature will be disabled by default. Alert dialogues will also no longer display the parameters submitted by the attacker, which could confuse users, instead only displaying the [...]]]></description>
		<content:encoded><![CDATA[<p>[...] applications&quot; feature will be disabled by default. Alert dialogues will also no longer display the parameters submitted by the attacker, which could confuse users, instead only displaying the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody</title>
		<link>http://blog.didierstevens.com/2010/06/29/quickpost-no-escape-from-pdf/#comment-39005</link>
		<dc:creator><![CDATA[Nobody]]></dc:creator>
		<pubDate>Tue, 29 Jun 2010 22:04:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=2178#comment-39005</guid>
		<description><![CDATA[Time to disclosure details about change pop-up message?]]></description>
		<content:encoded><![CDATA[<p>Time to disclosure details about change pop-up message?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

