Penetration Document Format Didier@DidierStevens.com - - PowerPoint PPT Presentation

penetration document format
SMART_READER_LITE
LIVE PREVIEW

Penetration Document Format Didier@DidierStevens.com - - PowerPoint PPT Presentation

Penetration Document Format Didier@DidierStevens.com Didier@DidierStevens.com Didier@DidierStevens.com Identification and Analysis Didier@DidierStevens.com Didier@DidierStevens.com PDFiD PDFiD 0.0.9 hello-world.pdf PDF Header: %PDF-1.1 obj


slide-1
SLIDE 1

Didier@DidierStevens.com

Penetration Document Format

slide-2
SLIDE 2

Didier@DidierStevens.com

slide-3
SLIDE 3

Didier@DidierStevens.com

slide-4
SLIDE 4

Didier@DidierStevens.com

Identification and Analysis

slide-5
SLIDE 5

Didier@DidierStevens.com

slide-6
SLIDE 6

Didier@DidierStevens.com

PDFiD 0.0.9 hello-world.pdf PDF Header: %PDF-1.1

  • bj 7

endobj 7 stream 1 endstream 1 xref 1 trailer 1 startxref 1 /Page 1 /Encrypt 0 /ObjStm 0 /JS 0 /JavaScript 0 /AA 0 /OpenAction 0 /AcroForm 0 /JBIG2Decode 0 /RichMedia 0 /Colors > 2^24 0

PDFiD

slide-7
SLIDE 7

Didier@DidierStevens.com

/Name Obfuscation

slide-8
SLIDE 8

Didier@DidierStevens.com

PDFiD Demo

slide-9
SLIDE 9

Didier@DidierStevens.com

http://www.Virustotal.com

slide-10
SLIDE 10

Didier@DidierStevens.com

slide-11
SLIDE 11

Didier@DidierStevens.com

http://blog.rootshell.be

slide-12
SLIDE 12

Didier@DidierStevens.com

In-The-Wild PDF

slide-13
SLIDE 13

Didier@DidierStevens.com

PoC Pure ASCII PDF

slide-14
SLIDE 14

Didier@DidierStevens.com

pdf-parser Demo

slide-15
SLIDE 15

Didier@DidierStevens.com

Protection

slide-16
SLIDE 16

Didier@DidierStevens.com

Foxit Reader

slide-17
SLIDE 17

Didier@DidierStevens.com

Sumatra PDF

slide-18
SLIDE 18

Didier@DidierStevens.com

Know Your Enemy ...

slide-19
SLIDE 19

Didier@DidierStevens.com

Disable JavaScript?

slide-20
SLIDE 20

Didier@DidierStevens.com

… Find His Achilles Heel

slide-21
SLIDE 21

Didier@DidierStevens.com

Access Tokens

slide-22
SLIDE 22

Didier@DidierStevens.com

Use Restricted Tokens

  • Windows >= Vista + UAC
  • DropMyRights
  • StripMyRights
  • SAFER SRP
slide-23
SLIDE 23

Didier@DidierStevens.com

Restricted Token in Action

slide-24
SLIDE 24

Didier@DidierStevens.com

Disclosure CVE-2009-2979

slide-25
SLIDE 25

Didier@DidierStevens.com

XML-Bomb in Metadata

slide-26
SLIDE 26

Didier@DidierStevens.com

Questions?

And hopefully some answers...

slide-27
SLIDE 27

Didier@DidierStevens.com

Thank you http://blog.DidierStevens.com