Processing Dangerous Paths - On Security and Privacy of the Portable Document Format
Jens Müller, Dominik Noss, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
摘要
—PDF is the de-facto standard for document exchange. It is common to open PDF files from potentially untrusted sources such as email attachments or downloaded from the Internet. In this work, we perform an in-depth analysis of the capabilities of malicious PDF documents. Instead of focusing on implementation bugs, we abuse legitimate features of the PDF standard itself by systematically identifying dangerous paths in the PDF file structure. These dangerous paths lead to attacks that we categorize into four generic classes: (1) Denial-of-Service attacks affecting the host that processes the document. (2) Information disclosure attacks leaking personal data out of the victim’s computer. (3) Data manipulation on the victim’s system. (4) Code execution on the victim’s machine. An evaluation of 28 popular PDF processing applications shows that 26 of them are vulnerable at least one attack. Finally, we propose a methodology to protect against attacks based on PDF features systematically.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- (In)Security of File Uploads in Node.jsHarun Oz, Abbas Acar, Ahmet Aris, Güliz Seray Tuncay 等WWW 2024 · 被引用 6 次
- Every Signature is Broken: On the Insecurity of Microsoft Office's OOXML SignaturesSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger 等USENIX Security 2023
- Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument SignaturesSimon Rohlmann, Christian Mainka, Vladislav Mladenov, Jörg SchwenkUSENIX Security 2022
它引用的顶会 Paper4
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising 等USENIX Security 2018 · 被引用 64 次
- Extract Me If You Can: Abusing PDF Parsers in Malware DetectorsCurtis Carmony, Xunchao Hu, Heng Yin, Abhishek Vasisht Bhaskar 等NDSS 2016 · 被引用 61 次
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
- PDF Mirage: Content Masking Attack Against Information-Based Online ServicesIan D. Markwood, Dakun Shen, Yao Liu, Zhuo LuUSENIX Security 2017 · 被引用 31 次
相关 Paper
- 1 Trillion Dollar Refund: How To Spoof PDF SignaturesVladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe 等CCS 2019 · 被引用 23 次
- Shadow Attacks: Hiding and Replacing Content in Signed PDFsChristian Mainka, Vladislav Mladenov, Simon RohlmannNDSS 2021
- Practical Decryption exFiltration: Breaking PDF EncryptionJens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka 等CCS 2019 · 被引用 18 次
- Breaking the Specification: PDF CertificationSimon Rohlmann, Vladislav Mladenov, Christian Mainka, Jörg SchwenkS&P 2021 · 被引用 16 次
- Analyzing PDFs like Binaries: Adversarially Robust PDF Malware Analysis via Intermediate Representation and Language ModelSide Liu, Jiang Ming, Guodong Zhou, Xinyi Liu 等CCS 2025
