Welcome Guest. | Log In| Register | Membership Benefits
Dark Reading's Evil Bytes Weblog
Topics:   Evil Bytes

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share

When PDFs And Flash Files Attack


Posted by John Sawyer, Jan 8, 2010 02:18 PM

It's getting harder to protect our users from threats coming at them from seemingly trusted places. The Websites they've been using for years are suddenly the source of attacks through malicious advertisements being pushed to the "trusted" site by a third-party advertising service. File format attacks against Adobe's Flash and Acrobat are becoming the exploit du jour for attackers.

The most recent attacks against Adobe Acrobat could be just the tip of the iceberg, according to a recent report. Analyzing these attacks is not always an easy task. One of the first steps is often to submit a suspicious Adobe Acrobat, Microsoft Word, or similar document types to Virus Total for analysis; however, the sensitivity of the environment may not allow for files to be sent outside for analysis.

If you're in that situation or are the type who just likes to get your hands dirty, then I've got some tools and resources to help you jump right into file analysis of Adobe Flash and Acrobat files. For Flash files, I typically use SWFTools to pull out strings that might indicate malicious intent, extract embedded files, and scripts. There is also Flare and a tool I just saw mentioned at Paul Melson's blog called Sothink SWF Decompiler, which looks promising.

Didier Stevens' PDF Tools are excellent for dealing with PDFs that you suspect are malicious. It's important that I point out these tools don't tell you whether the file contains something malicious. They are analysis tools to help you make that determination. To help you better understand what they can do for you, take a look at the recent analysis write-ups at the Internet Storm Center here and here.

As you can see from the ISC examples, analyzing files looking for maliciousness is not an easy task. The tools are available if you're up to the challenge, and with the current PDF-based attacks, there are plenty of samples to analyze.

John H. Sawyer is a senior security engineer on the IT Security Team at the University of Florida. The views and opinions expressed in this blog are his own and do not represent the views and opinions of the UF IT Security Team or the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other. Special to Dark Reading.

« Adobe Reader's Patch Tuesday | Main | The Inconvenient Truth Behind Security »



Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








  1. Block Windows Shortcut Exploit Without Losing Your Shortcut Icons
  2. The Cash Drawer Lock Box And SMB Security
  3. Would 'Robin Sage' Have Made So Many Friends Without The Hot Pics?
  4. Security BSides Grows, But Not Too Much
  5. Conquering Large Web Apps With Solid Methodology

  1. Malware Authors Leave Their Fingerprints On Their Work, Black Hat Researcher Says
  2. Black Hat USA 2010: Complete Coverage
  3. Predicted Fallout Following WikiLeaks Video
  4. ATMs At Risk, Researcher Warns At Black Hat
  5. Internet Infrastructure Reaches Long-Awaited Security Milestone
  6. Researcher Exposes Massive Automated Check Counterfeiting Operation Out of Russia

  1. Desktop Software Lockdown: Prevent Zero-Day Attacks
  2. INETCO Insight of the Week #5 - Combating The "Data Dilemma" with INETCO Insight
  3. Best Practices When Enabling Smart Card Authentication in a KVM System
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  OCTOBER 2008
SEPTEMBER 2008
APRIL 2008
NOVEMBER 2007
  OCTOBER 2007
AUGUST 2007
MARCH 2007
OCTOBER 2006