SlideShare a Scribd company logo
1 of 27
Download to read offline
Didier@DidierStevens.com
Penetration Document Format
Didier@DidierStevens.com
Didier@DidierStevens.com
Didier@DidierStevens.com
Identification and Analysis
Didier@DidierStevens.com
Didier@DidierStevens.com
PDFiD 0.0.9 hello-world.pdf
PDF Header: %PDF-1.1
obj 7
endobj 7
stream 1
endstream 1
xref 1
trailer 1
startxref 1
/Page 1
/Encrypt 0
/ObjStm 0
/JS 0
/JavaScript 0
/AA 0
/OpenAction 0
/AcroForm 0
/JBIG2Decode 0
/RichMedia 0
/Colors > 2^24 0
PDFiD
Didier@DidierStevens.com
/Name Obfuscation
Didier@DidierStevens.com
PDFiD Demo
Didier@DidierStevens.com
http://www.Virustotal.com
Didier@DidierStevens.com
Didier@DidierStevens.com
http://blog.rootshell.be
Didier@DidierStevens.com
In-The-Wild PDF
Didier@DidierStevens.com
PoC Pure ASCII PDF
Didier@DidierStevens.com
pdf-parser Demo
Didier@DidierStevens.com
Protection
Didier@DidierStevens.com
Foxit Reader
Didier@DidierStevens.com
Sumatra PDF
Didier@DidierStevens.com
Know Your Enemy ...
Didier@DidierStevens.com
Disable JavaScript?
Didier@DidierStevens.com
… Find His Achilles Heel
Didier@DidierStevens.com
Access Tokens
Didier@DidierStevens.com
Use Restricted Tokens
● Windows >= Vista + UAC
● DropMyRights
● StripMyRights
● SAFER SRP
Didier@DidierStevens.com
Restricted Token in Action
Didier@DidierStevens.com
Disclosure CVE-2009-2979
Didier@DidierStevens.com
XML-Bomb in Metadata
Didier@DidierStevens.com
Questions?
And hopefully some answers...
Didier@DidierStevens.com
Thank you
http://blog.DidierStevens.com

More Related Content

Viewers also liked

Plafons colonies la sinia
Plafons colonies la sinia Plafons colonies la sinia
Plafons colonies la sinia meganuke94
 
8. jesús mostraba simpatía
8. jesús mostraba simpatía8. jesús mostraba simpatía
8. jesús mostraba simpatíaA L
 
Велопрокат в парке "Сокольники"
Велопрокат в парке "Сокольники"Велопрокат в парке "Сокольники"
Велопрокат в парке "Сокольники"Event-agency C4group
 
Rachel Fullmer-portfolio
Rachel Fullmer-portfolioRachel Fullmer-portfolio
Rachel Fullmer-portfolioskeez0526
 
2. crisis en el edén
2. crisis en el edén2. crisis en el edén
2. crisis en el edénA L
 
Cf 8 blocks of success training1
Cf 8 blocks of success training1Cf 8 blocks of success training1
Cf 8 blocks of success training1Muhammed Eid
 
12. los últimos días de jesús
12. los últimos días de jesús12. los últimos días de jesús
12. los últimos días de jesúsA L
 
WordPress 3.6 New Features
WordPress 3.6 New FeaturesWordPress 3.6 New Features
WordPress 3.6 New Featuresmasmanx
 
The busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterestThe busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterestBestsellerSociety
 

Viewers also liked (15)

Plafons colonies la sinia
Plafons colonies la sinia Plafons colonies la sinia
Plafons colonies la sinia
 
8. jesús mostraba simpatía
8. jesús mostraba simpatía8. jesús mostraba simpatía
8. jesús mostraba simpatía
 
Велопрокат в парке "Сокольники"
Велопрокат в парке "Сокольники"Велопрокат в парке "Сокольники"
Велопрокат в парке "Сокольники"
 
Chimney & Flue Systems MF Brocure
Chimney & Flue Systems MF BrocureChimney & Flue Systems MF Brocure
Chimney & Flue Systems MF Brocure
 
Rachel Fullmer-portfolio
Rachel Fullmer-portfolioRachel Fullmer-portfolio
Rachel Fullmer-portfolio
 
2. crisis en el edén
2. crisis en el edén2. crisis en el edén
2. crisis en el edén
 
Coal train fact_check
Coal train fact_checkCoal train fact_check
Coal train fact_check
 
Spyddr
SpyddrSpyddr
Spyddr
 
Cf 8 blocks of success training1
Cf 8 blocks of success training1Cf 8 blocks of success training1
Cf 8 blocks of success training1
 
flue dilution solution
 flue dilution solution  flue dilution solution
flue dilution solution
 
12. los últimos días de jesús
12. los últimos días de jesús12. los últimos días de jesús
12. los últimos días de jesús
 
WordPress 3.6 New Features
WordPress 3.6 New FeaturesWordPress 3.6 New Features
WordPress 3.6 New Features
 
76216 99253-1-pb
76216 99253-1-pb76216 99253-1-pb
76216 99253-1-pb
 
Social Media for Business
Social Media for BusinessSocial Media for Business
Social Media for Business
 
The busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterestThe busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterest
 

More from Steph Cliche

Sc2014 proceedings
Sc2014 proceedingsSc2014 proceedings
Sc2014 proceedingsSteph Cliche
 
Safes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locksSafes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locksSteph Cliche
 
Ieee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systemsIeee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systemsSteph Cliche
 
Ieee interference-measurements-802.11n
Ieee interference-measurements-802.11nIeee interference-measurements-802.11n
Ieee interference-measurements-802.11nSteph Cliche
 
Guardi final report
Guardi final reportGuardi final report
Guardi final reportSteph Cliche
 
2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodataSteph Cliche
 
Tmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hackluTmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hackluSteph Cliche
 
Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013Steph Cliche
 
013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_eSteph Cliche
 
Hack.lu 09 ip-morph
Hack.lu 09 ip-morphHack.lu 09 ip-morph
Hack.lu 09 ip-morphSteph Cliche
 
7 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.07 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.0Steph Cliche
 
Global maritime-security
Global maritime-securityGlobal maritime-security
Global maritime-securitySteph Cliche
 

More from Steph Cliche (20)

Spy pack
Spy packSpy pack
Spy pack
 
Sc2014 proceedings
Sc2014 proceedingsSc2014 proceedings
Sc2014 proceedings
 
Sat howto
Sat howtoSat howto
Sat howto
 
Satellite hacking
Satellite hackingSatellite hacking
Satellite hacking
 
Safes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locksSafes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locks
 
Ieee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systemsIeee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systems
 
Ieee interference-measurements-802.11n
Ieee interference-measurements-802.11nIeee interference-measurements-802.11n
Ieee interference-measurements-802.11n
 
Guardi final report
Guardi final reportGuardi final report
Guardi final report
 
718001 000 en
718001 000 en718001 000 en
718001 000 en
 
2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata
 
Tmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hackluTmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hacklu
 
Public wifi
Public wifiPublic wifi
Public wifi
 
Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013
 
013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e
 
Hack.lu 09 ip-morph
Hack.lu 09 ip-morphHack.lu 09 ip-morph
Hack.lu 09 ip-morph
 
12
1212
12
 
09 09 2014
09 09 201409 09 2014
09 09 2014
 
7 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.07 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.0
 
Global maritime-security
Global maritime-securityGlobal maritime-security
Global maritime-security
 
Future war
Future warFuture war
Future war
 

Penetration document format slides