[Full-disclosure] Adobe Acrobat Default Behavior Ignores Systems Defaults

FullDis.20.mandoskippy_at_spamgourmet.com
Date: 03/22/05

  • Next message: Burak DAYIOGLU: "[Full-disclosure] Re: Nortel VPN Client Issue: Clear-text password stored in memory"
    To: full-disclosure@lists.grok.org.uk
    Date: Tue, 22 Mar 2005 15:00:11 -0600
    
    
    

    In Adobe Acrobat 7.0, if there is a link in a PDF file, clicking on the link
    opens it in Internet Explorer regardless of the default browser set on the
    PC. Although relatively minor, this could be used in a social engineering
    attack (albeit a very specifically crafted attack) to get a savvy computer
    user running an alternative browser for security reasons, to open a link to
    a malicious site in Internet Explorer. Adobe has been notified and has not
    responded with any sort of "human" response. Note: Even Microsoft Word will
    open a link in the default browser so this behavior should not be "by
    design".

     

    MandoSkippy

     

     

     

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Burak DAYIOGLU: "[Full-disclosure] Re: Nortel VPN Client Issue: Clear-text password stored in memory"

    Relevant Pages

    • browser preference
      ... "Internet explorer cannot find the ... >"Internet Explorer and Netscape Navigator both want your ... >take over for the other as the default browser each time ... >default browser is the one that automatically opens when ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • RE: OPEN WITH not working.
      ... Internet Explorer checks to see if it is the default browser ... it shows "Opens with: Internet Explorer". ... This posting is provided "AS IS" with no warranties, ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Default settings
      ... If nothing else opens in its place then nothing has taken it's place. ... Explorer is not currently the default browser, do you wish to make it so, ... "Internet Explorer should check to see whether it is the default browser." ... See if this also stops the Outlook Express dialog. ...
      (microsoft.public.windowsxp.accessibility)
    • Spyware or bad driver?
      ... I'm working on a friends computer: XP Home Internet Explorer 6. ... Clicking the "X" to close a browser window, only opens another. ... refresh itself. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • RE: IE as my default browser
      ... I think that your Internet Explorer is the default browser, ... > when you go to the internet, IE6 opens up automatically? ... > bar in order for it to open a browser page. ...
      (microsoft.public.windowsxp.general)