penetration document format slides

27
[email protected] Penetration Document Format

Upload: steph-cliche

Post on 16-Jul-2015

72 views

Category:

Documents


2 download

TRANSCRIPT

[email protected]

Penetration Document Format

[email protected]

Identification and Analysis

[email protected]

PDFiD 0.0.9 hello-world.pdf PDF Header: %PDF-1.1 obj 7 endobj 7 stream 1 endstream 1 xref 1 trailer 1 startxref 1 /Page 1 /Encrypt 0 /ObjStm 0 /JS 0 /JavaScript 0 /AA 0 /OpenAction 0 /AcroForm 0 /JBIG2Decode 0 /RichMedia 0 /Colors > 2^24 0

PDFiD

[email protected]

/Name Obfuscation

[email protected]

PDFiD Demo

[email protected]

http://www.Virustotal.com

[email protected]

http://blog.rootshell.be

[email protected]

In-The-Wild PDF

[email protected]

PoC Pure ASCII PDF

[email protected]

pdf-parser Demo

[email protected]

Protection

[email protected]

Foxit Reader

[email protected]

Sumatra PDF

[email protected]

Know Your Enemy ...

[email protected]

Disable JavaScript?

[email protected]

… Find His Achilles Heel

[email protected]

Access Tokens

[email protected]

Use Restricted Tokens

● Windows >= Vista + UAC● DropMyRights● StripMyRights● SAFER SRP

[email protected]

Restricted Token in Action

[email protected]

Disclosure CVE-2009-2979

[email protected]

XML-Bomb in Metadata

[email protected]

Questions?

And hopefully some answers...

[email protected]

Thank you

http://blog.DidierStevens.com