Re: Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged

From: Dan Harkless (bugtraq@harkless.org)
Date: 03/26/03

  • Next message: Kevin: "Re: PHPNuke viewpage.php allows Remote File retrieving"
    From: "Dan Harkless" <bugtraq@harkless.org>
    To: bugtraq@securityfocus.com
    Date: Wed, 26 Mar 2003 10:35:13 -0800
    

    Vladimir Katalov <info@elcomsoft.com> writes:
    > We were able to write a 'fake' plug-in "fakecert.api" which does
    > nothing, but being loaded by Adobe Acrobat (and Reader) 4 and 5
    > as the certified one even in 'trusted' mode, though we don't have
    > a 'Reader Integration Key' (this plug-in has been provided only to
    > Adobe and CERT). When installed into 'plug_ins' subfolder, plug-in
    > is being loaded every time when Adobe Acrobat (or Reader) starts, and
    > shows a simple message box.

    For those of us not familiar with Acrobat plugins, is there some facility
    for the program retrieving/installing plugins automatically, or, to exploit
    this would you need to entice a user to manually place your .api file in
    their "plug_ins" directory (or run an installer program that would do so, in
    which case you could run arbitrary code anyway in the installer)?

    --
    Dan Harkless
    bugtraq@harkless.org
    http://harkless.org/dan/
    

  • Next message: Kevin: "Re: PHPNuke viewpage.php allows Remote File retrieving"

    Relevant Pages

    • Re: Cant view .PDF files in IE6
      ... What version of Adobe Acrobat (Reader) are you ... > Thanks PA Bear. ... im still not able to access the PDFs thru IE. I'm ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Convert MS word to PDf
      ... The best is probably Adobe Acrobat ... "Doug Freese" wrote in message ... > to put it into PDF for it's compaction plus the Adobe reader is free. ...
      (microsoft.public.word.formatting.longdocs)
    • Re: adobe reader
      ... Hey, you can still use Adobe Acrobat to read PDF files,. ... Since when have you had to purchase more expensive Acrobat Readers? ... Reader, which commonly offered for download on many web sites. ...
      (microsoft.public.windowsxp.general)
    • Re: ActiveX-Control des Adobe Reader 7.0
      ... Registriervorgang erfolglos war. ... Bei den Versionen 4-6 des Adobe Acrobat ... Adobe Acrobat Reader Installation. ... Wir setzen in der Firma weiterhin das ActiveX Steuerelement zur Anzeige ...
      (de.comp.lang.delphi.misc)
    • Re: Verwendung von Spaltenname in NOT LIKE Abfrage
      ... > Adobe Acrobat Reader 5.0 ... > Quick Time Player 2.0 ... > Diese Worte habe ich in einer zweiten Tabelle Tabelle 2 ...
      (microsoft.public.de.access)