> I didn't think PDF files could contain executable code.
Sadly this is how most attacks against {file formats, protocols, standards} work.
- Lots of parts of the Unicode spec (LTR/RTL swap, phishing attacks with homographs)
- Interpretation of character set by browser+server
- XML External Entities to do XXE
- YAML references to create YAMLBombs
- Zip massive compression ratios to create ZIP bombs
- JWT where user assigns no encryption algorithm
- PHP accepting URLs from user then piping them to PHP filters
- file upload with polymorphic files
- file upload where filename suffix doesn't match magic bytes
> Are PDFs as attack vectors common?
This is not news. PDF-based attacks against Acrobat / Acrobat Reader, FoxIt, etc have been common for over a decade.
> Files based on Reader were exploited in almost 49 per cent of the targeted attacks of 2009[1]
> According to a newly released report by Symantec's MessageLabs, malicious PDF files outpace the distribution of related malicious attachments used in targeted attacks.[2] (2011)
Sadly this is how most attacks against {file formats, protocols, standards} work.
> Are PDFs as attack vectors common?This is not news. PDF-based attacks against Acrobat / Acrobat Reader, FoxIt, etc have been common for over a decade.
> Files based on Reader were exploited in almost 49 per cent of the targeted attacks of 2009[1]
> According to a newly released report by Symantec's MessageLabs, malicious PDF files outpace the distribution of related malicious attachments used in targeted attacks.[2] (2011)
> JavaScript and XFA Forms / Adobe LifeCycle[3]
[1] https://www.schneier.com/blog/archives/2010/03/pdf_the_most_...
[2] https://www.zdnet.com/article/report-malicious-pdf-files-bec...
[3] https://www.sentinelone.com/blog/malicious-pdfs-revealing-te...