Caros,
Faz um tempo desde o último post mas a vida anda corrida por esses lados . Faço esse post para comentar mais 2 palestras aceitas só que agora no Brasil felizmente .
A primeira ocorrerá no OWASP AppSec Brasil que acontecerá em Campinas onde falarei do uso do Modsecurity WAF para Virtual Patching ( http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Speakers)
Mais info: http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Calls
Outra que tive o prazer de ser aceito e falarei pela primeira vez sera a Hackers to Hackers Conference aka H2HC . Nela falarei sobre minha pdf de scoring da estrutura do pdf o que me deixa bem feliz de falar sobre ela por aqui também.
Mais info: http://www.h2hc.com.br
Espero encontrar com vocês lá .
Happy Hacking!
Rodrigo "Sp0oKeR" Montoro
Here I will post some security tips, articles / paper mine or from other blogs that I think interested . I Iove computer subjects related in special: - Penetration Tests - Network Intrusion Detection and Prevention - Network Behaviour - SIEM - Network Security Monitoring (NSM) - Incident Response - Firewall, - Host Intrusion Detection System - The Open Web Application Security Project (OWASP) - Capitulo Brasil - fuzzing - Vulnerability - Packet Analisys - Log Analysis - Beer =)
Mostrando postagens com marcador pdf. Mostrar todas as postagens
Mostrando postagens com marcador pdf. Mostrar todas as postagens
quarta-feira, 6 de outubro de 2010
quarta-feira, 8 de setembro de 2010
PDF Talk Accepted at Toorcon San Diego
I'm very excited that my talk was accepted at Toorcon San Diego. About the conference:
Who: Hackers Like You.
What: ToorCon 12
When: OCT 22rd-24th
Where: San Diego Convention Center
Why: What Could possibly go wrong?
I'll be talking about part of my research at Trustwave Spiderlabs Research where we are doing a new way to detect malicious pdf files . The title for my talk: "Scoring PDF structure to detect malicious files"
Preliminary Agenda for Toorcon: http://sandiego.toorcon.org/index.php?option=com_content&task=section&id=3&Itemid=9#lineup
Hope to see you there!
Rodrigo "Sp0oKeR" Montoro
Who: Hackers Like You.
What: ToorCon 12
When: OCT 22rd-24th
Where: San Diego Convention Center
Why: What Could possibly go wrong?
I'll be talking about part of my research at Trustwave Spiderlabs Research where we are doing a new way to detect malicious pdf files . The title for my talk: "Scoring PDF structure to detect malicious files"
Preliminary Agenda for Toorcon: http://sandiego.toorcon.org/index.php?option=com_content&task=section&id=3&Itemid=9#lineup
Hope to see you there!
Rodrigo "Sp0oKeR" Montoro
Marcadores:
conferences,
pdf,
spiderlabs
segunda-feira, 16 de agosto de 2010
SET (Social Engineer Toolkit) PDF’s x AntiVirus & Scoring System
Since Social Engineer Toolkit aka SET is being using in the wild I solved to create their pdf’s and tests against AntiVirus Vendors and against new detection scoring based on Spiderlabs Research .
[---] The Social-Engineer Toolkit (SET) [---]
[---] Written by David Kennedy (ReL1K) [---]
[---] Version: 0.6.1 [---]
[---] Codename: 'Arnold Palmer' [---]
[---] Report bugs to: davek@social-engineer.org [---]
[---] Java Applet Written by: Thomas Werth [---]
[---] Homepage: http://www.secmaniac.com [---]
[---] Framework: http://www.social-engineer.org [---]
[---] Over 1 million downloads and counting. [---]
Welcome to the Social-Engineer Toolkit (SET). Your one
stop shop for all of your social-engineering needs..
Follow me on Twitter: dave_rel1k
DerbyCon 2011 Sep29-Oct02 - A new era begins...
http://www.derbycon.com
Select from the menu on what you would like to do:
1. Spear-Phishing Attack Vectors
2. Website Attack Vectors
3. Infectious Media Generator
4. Create a Payload and Listener
5. Mass Mailer Attack
6. Teensy USB HID Attack Vector
7 Update the Metasploit Framework
8. Update the Social-Engineer Toolkit
9. Help, Credits, and About
10. Exit the Social-Engineer Toolkit
Enter your choice: 1
1. Perform a Mass Email Attack
2. Create a FileFormat Payload
3. Create a Social-Engineering Template
4. Return to Main Menu
Enter your choice: 1
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
2. Adobe Collab.collectEmailInfo Buffer Overflow
3. Adobe Collab.getIcon Buffer Overflow
4. Adobe JBIG2Decode Memory Corruption Exploit
5. Adobe PDF Embedded EXE Social Engineering
6. Adobe util.printf() Buffer Overflow
7. Custom EXE to VBA (sent via RAR) (RAR required)
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
Enter the number you want (press enter for default):
1. Windows Reverse TCP Shell
2. Windows Meterpreter Reverse_TCP
3. Windows Reverse VNC
4. Windows Reverse TCP Shell (x64)
5. Windows Meterpreter Reverse_TCP (X64)
6. Windows Shell Bind_TCP (X64)
Enter the payload you want (press enter for default):
* All payload 1 – Windows Reverse TCP Shell with port 2345
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
http://www.virustotal.com/file-scan/report.html?id=377ba41782bbeb25c9816d76ec190fb6f4b88c7bbaecc26653a4a6ecc479f3ea-1281835639
File name:flashplayer-newfunction.pdf
Submission date: 2010-08-15 01:27:19 (UTC)
Result: 15/ 42 (35.7%)
$ pdf-analisys.pl -s1 -f flashplayer-newfunction.pdf
flashplayer-newfunction.pdf Malicious PDF Detected
2. Adobe Collab.collectEmailInfo Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=a4ac73a6efee530a05ea05eeeaa3d8efc137e4eb3bcf4d492c2b318264da2f77-1281836155
File name: collab-collectEmailInfo.pdf
Submission date: 2010-08-15 01:35:55 (UTC)
Result: 17/ 42 (40.5%)
$ pdf-analisys.pl -s1 -f collab-collectEmailInfo.pdf
collab-collectEmailInfo.pdf Malicious PDF Detected
3. Adobe Collab.getIcon Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=631893cd75bcf60ec82a3f59d3bd3f7f166874641a4ed62ceee28852889ec6e2-1281836494
File name: collab-getIcon.pdf
Submission date: 2010-08-15 01:41:34 (UTC)
Result: 15/ 42 (35.7%)
pdf-analisys.pl -s1 -f collab-getIcon.pdf
collab-getIcon.pdf Malicious PDF Detected
4. Adobe JBIG2Decode Memory Corruption Exploit
http://www.virustotal.com/file-scan/report.html?id=814f20d28de287e76dbfacb14d90dbfab8e0b1e11e16212b88ca3216f2189117-1281836756
File name: JBIG2Decode.pdf
Submission date: 2010-08-15 01:45:56 (UTC)
Result: 15/ 42 (35.7%)
$ pdf-analisys.pl -s1 -f JBIG2Decode.pdf
JBIG2Decode.pdf Malicious PDF Detected
5. Adobe PDF Embedded EXE Social Engineering
http://www.virustotal.com/file-scan/report.html?id=484ba7800fd549b82b6ac4dab5100f3017a0995cc47be13977703a168d1bcef3-1281837936
File name: embeddedfile.pdf
Submission date: 2010-08-15 02:05:36 (UTC)
Result: 15/ 41 (36.6%)
$ pdf-analisys.pl -s1 -f embeddedfile.pdf
embeddedfile.pdf Malicious PDF Detected
6. Adobe util.printf() Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=99e01802391f77c5c93cdf52cb2eacb5673e6acf7ac90776d477948a7fa1222d-1281838414
File name: utilprintf.pdf
Submission date: 2010-08-15 02:13:34 (UTC)
Result: 16/ 42 (38.1%)
$ pdf-analisys.pl -s1 -f utilprintf.pdf
utilprintf.pdf Malicious PDF Detected
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
http://www.virustotal.com/file-scan/report.html?id=0ce18c65373f113916b108508b3afc481e460f77353d1e3ddd259dbd29bab5a1-1281838713
File name: U3D.pdf
Submission date: 2010-08-15 02:18:33 (UTC)
Result: 11/ 42 (26.2%)
pdf-analisys.pl -s1 -f U3D.pdf
U3D.pdf Malicious PDF Detected
Clamav Results
collab-collectEmailInfo.pdf: OK
collab-getIcon.pdf: OK
embeddedfile.pdf: Exploit.PDF-22612 FOUND
flashplayer-newfunction.pdf: OK
JBIG2Decode.pdf: OK
U3D.pdf: OK
utilprintf.pdf: OK
----------- SCAN SUMMARY -----------
Known viruses: 813894
Engine version: 0.96.1
Scanned files: 7
Infected files: 1
* Clamav just updated to new engine 0.96.2 that detected all 7 samples as malicious so UPDATE your engine ASAP .
Virus Total Results
Result: 15/ 42 (35.7%)
Result: 17/ 42 (40.5%)
Result: 15/ 42 (35.7%)
Result: 15/ 42 (35.7%)
Result: 15/ 41 (36.6%)
Result: 16/ 42 (38.1%)
Result: 11/ 42 (26.2%)
Average Detection: 14,85 / 42 or 35,37%
Top5* AntiVirus Results
* Top5 antivirus based on most common names not in detection rates
** Payloads listed bellow:
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
2. Adobe Collab.collectEmailInfo Buffer Overflow
3. Adobe Collab.getIcon Buffer Overflow
4. Adobe JBIG2Decode Memory Corruption Exploit
5. Adobe PDF Embedded EXE Social Engineering
6. Adobe util.printf() Buffer Overflow
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
Scoring System Results
collab-collectEmailInfo.pdf Malicious PDF Detected
collab-getIcon.pdf Malicious PDF Detected
embeddedfile.pdf Malicious PDF Detected
flashplayer-newfunction.pdf Malicious PDF Detected
JBIG2Decode.pdf Malicious PDF Detected
U3D.pdf Malicious PDF Detected
utilprintf.pdf Malicious PDF Detected
We sent some papers to a couple of conferences to star to share those information . I’ll let you know if we get approve and where =) .
Let’s keep improving our research and sharing each time more and more information. In the future we’ll share all the information , scoring and parser .
Regards,
Rodrigo "Sp0oKeR" Montoro
[---] The Social-Engineer Toolkit (SET) [---]
[---] Written by David Kennedy (ReL1K) [---]
[---] Version: 0.6.1 [---]
[---] Codename: 'Arnold Palmer' [---]
[---] Report bugs to: davek@social-engineer.org [---]
[---] Java Applet Written by: Thomas Werth [---]
[---] Homepage: http://www.secmaniac.com [---]
[---] Framework: http://www.social-engineer.org [---]
[---] Over 1 million downloads and counting. [---]
Welcome to the Social-Engineer Toolkit (SET). Your one
stop shop for all of your social-engineering needs..
Follow me on Twitter: dave_rel1k
DerbyCon 2011 Sep29-Oct02 - A new era begins...
http://www.derbycon.com
Select from the menu on what you would like to do:
1. Spear-Phishing Attack Vectors
2. Website Attack Vectors
3. Infectious Media Generator
4. Create a Payload and Listener
5. Mass Mailer Attack
6. Teensy USB HID Attack Vector
7 Update the Metasploit Framework
8. Update the Social-Engineer Toolkit
9. Help, Credits, and About
10. Exit the Social-Engineer Toolkit
Enter your choice: 1
1. Perform a Mass Email Attack
2. Create a FileFormat Payload
3. Create a Social-Engineering Template
4. Return to Main Menu
Enter your choice: 1
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
2. Adobe Collab.collectEmailInfo Buffer Overflow
3. Adobe Collab.getIcon Buffer Overflow
4. Adobe JBIG2Decode Memory Corruption Exploit
5. Adobe PDF Embedded EXE Social Engineering
6. Adobe util.printf() Buffer Overflow
7. Custom EXE to VBA (sent via RAR) (RAR required)
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
Enter the number you want (press enter for default):
1. Windows Reverse TCP Shell
2. Windows Meterpreter Reverse_TCP
3. Windows Reverse VNC
4. Windows Reverse TCP Shell (x64)
5. Windows Meterpreter Reverse_TCP (X64)
6. Windows Shell Bind_TCP (X64)
Enter the payload you want (press enter for default):
* All payload 1 – Windows Reverse TCP Shell with port 2345
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
http://www.virustotal.com/file-scan/report.html?id=377ba41782bbeb25c9816d76ec190fb6f4b88c7bbaecc26653a4a6ecc479f3ea-1281835639
File name:flashplayer-newfunction.pdf
Submission date: 2010-08-15 01:27:19 (UTC)
Result: 15/ 42 (35.7%)
$ pdf-analisys.pl -s1 -f flashplayer-newfunction.pdf
flashplayer-newfunction.pdf Malicious PDF Detected
2. Adobe Collab.collectEmailInfo Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=a4ac73a6efee530a05ea05eeeaa3d8efc137e4eb3bcf4d492c2b318264da2f77-1281836155
File name: collab-collectEmailInfo.pdf
Submission date: 2010-08-15 01:35:55 (UTC)
Result: 17/ 42 (40.5%)
$ pdf-analisys.pl -s1 -f collab-collectEmailInfo.pdf
collab-collectEmailInfo.pdf Malicious PDF Detected
3. Adobe Collab.getIcon Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=631893cd75bcf60ec82a3f59d3bd3f7f166874641a4ed62ceee28852889ec6e2-1281836494
File name: collab-getIcon.pdf
Submission date: 2010-08-15 01:41:34 (UTC)
Result: 15/ 42 (35.7%)
pdf-analisys.pl -s1 -f collab-getIcon.pdf
collab-getIcon.pdf Malicious PDF Detected
4. Adobe JBIG2Decode Memory Corruption Exploit
http://www.virustotal.com/file-scan/report.html?id=814f20d28de287e76dbfacb14d90dbfab8e0b1e11e16212b88ca3216f2189117-1281836756
File name: JBIG2Decode.pdf
Submission date: 2010-08-15 01:45:56 (UTC)
Result: 15/ 42 (35.7%)
$ pdf-analisys.pl -s1 -f JBIG2Decode.pdf
JBIG2Decode.pdf Malicious PDF Detected
5. Adobe PDF Embedded EXE Social Engineering
http://www.virustotal.com/file-scan/report.html?id=484ba7800fd549b82b6ac4dab5100f3017a0995cc47be13977703a168d1bcef3-1281837936
File name: embeddedfile.pdf
Submission date: 2010-08-15 02:05:36 (UTC)
Result: 15/ 41 (36.6%)
$ pdf-analisys.pl -s1 -f embeddedfile.pdf
embeddedfile.pdf Malicious PDF Detected
6. Adobe util.printf() Buffer Overflow
http://www.virustotal.com/file-scan/report.html?id=99e01802391f77c5c93cdf52cb2eacb5673e6acf7ac90776d477948a7fa1222d-1281838414
File name: utilprintf.pdf
Submission date: 2010-08-15 02:13:34 (UTC)
Result: 16/ 42 (38.1%)
$ pdf-analisys.pl -s1 -f utilprintf.pdf
utilprintf.pdf Malicious PDF Detected
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
http://www.virustotal.com/file-scan/report.html?id=0ce18c65373f113916b108508b3afc481e460f77353d1e3ddd259dbd29bab5a1-1281838713
File name: U3D.pdf
Submission date: 2010-08-15 02:18:33 (UTC)
Result: 11/ 42 (26.2%)
pdf-analisys.pl -s1 -f U3D.pdf
U3D.pdf Malicious PDF Detected
Clamav Results
collab-collectEmailInfo.pdf: OK
collab-getIcon.pdf: OK
embeddedfile.pdf: Exploit.PDF-22612 FOUND
flashplayer-newfunction.pdf: OK
JBIG2Decode.pdf: OK
U3D.pdf: OK
utilprintf.pdf: OK
----------- SCAN SUMMARY -----------
Known viruses: 813894
Engine version: 0.96.1
Scanned files: 7
Infected files: 1
* Clamav just updated to new engine 0.96.2 that detected all 7 samples as malicious so UPDATE your engine ASAP .
Virus Total Results
Result: 15/ 42 (35.7%)
Result: 17/ 42 (40.5%)
Result: 15/ 42 (35.7%)
Result: 15/ 42 (35.7%)
Result: 15/ 41 (36.6%)
Result: 16/ 42 (38.1%)
Result: 11/ 42 (26.2%)
Average Detection: 14,85 / 42 or 35,37%
Top5* AntiVirus Results
* Top5 antivirus based on most common names not in detection rates
** Payloads listed bellow:
1. Adobe Flash Player 'newfunction' Invalid Pointer Use
2. Adobe Collab.collectEmailInfo Buffer Overflow
3. Adobe Collab.getIcon Buffer Overflow
4. Adobe JBIG2Decode Memory Corruption Exploit
5. Adobe PDF Embedded EXE Social Engineering
6. Adobe util.printf() Buffer Overflow
8. Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
Scoring System Results
collab-collectEmailInfo.pdf Malicious PDF Detected
collab-getIcon.pdf Malicious PDF Detected
embeddedfile.pdf Malicious PDF Detected
flashplayer-newfunction.pdf Malicious PDF Detected
JBIG2Decode.pdf Malicious PDF Detected
U3D.pdf Malicious PDF Detected
utilprintf.pdf Malicious PDF Detected
We sent some papers to a couple of conferences to star to share those information . I’ll let you know if we get approve and where =) .
Let’s keep improving our research and sharing each time more and more information. In the future we’ll share all the information , scoring and parser .
Regards,
Rodrigo "Sp0oKeR" Montoro
sexta-feira, 23 de julho de 2010
Updates/New Features at ViCheck and VirusTotal
This week those nice online tools made great enhancements specially ViCheck
From ViCheck Blog:
For recently processed documents such as PDF or MS Office (engine >=193) we are now highlighting more information about the embedded executable such as the encryption/cipher method and information about the key.
To read and see samples about those:
http://vicheck.blogspot.com/2010/07/email-report-enhancements.html
http://vicheck.blogspot.com/2010/07/report-page-enhancements.html
From Virus Total Blog:
They added new engine from SUPERAntiSpyware ( http://www.superantispyware.com/ ) what I help to improve the AV detection rates. Hope it's something not too static only . I really never heard about this engine before .
To read about this: http://blog.hispasec.com/virustotal/49
Happy Hacking!
Rodrigo Montoro (Sp0oKeR)
From ViCheck Blog:
Report page enhancements and Email Report
To read and see samples about those:
http://vicheck.blogspot.com/2010/07/email-report-enhancements.html
http://vicheck.blogspot.com/2010/07/report-page-enhancements.html
From Virus Total Blog:
They added new engine from SUPERAntiSpyware ( http://www.superantispyware.com/ ) what I help to improve the AV detection rates. Hope it's something not too static only . I really never heard about this engine before .
To read about this: http://blog.hispasec.com/virustotal/49
Happy Hacking!
Rodrigo Montoro (Sp0oKeR)
segunda-feira, 19 de julho de 2010
Malicious PDF not detected by any antivirus signature (Updated/Incorrect)
Please read the new post explaining what this post was wrong
http://spookerlabs.blogspot.com/2010/07/not-malicious-pdf-which-online-tool.html
Regards,
Today I got something curious in my PDF analysis:
@2gg a friend from twitter sent me some samples and 3 of them I tried to run against VirusTotal to make sure my research isn't generating False Positives(FP). For my surprise I uploaded a file to there and I got the detection Results: 0/43 .
File name: c0610pall_MPA_Kit.re.pdf
Submission date: 2010-07-15 15:42:59 (UTC)
Current status: queued queued analysing finished

Result: 0/ 43 (0.0%)
Our Research result was:
/LABS/pdf-basics$ perl pdf-analisys.pl -f c0610pall_MPA_Kit.re.pdf
c0610pall_MPA_Kit.re.pdf Malicious PDF Detected
That means that my script was generating a FP but based on analysis using Didier Stevens tools I was thinking that Antivirus failed totally against this sample.
So I ran the PDF against jsunpack-n to have a third test and I got:
$ ./jsunpackn.py c0610pall_MPA_Kit.re.pdf -V
[suspicious:3] [PDF] c0610pall_MPA_Kit.re.pdf.maybe.vir
suspicious: getAnnots CVE-2009-1492 detected
info: [decodingLevel=0] JavaScript in PDF 1298 bytes, with 1329 bytes headers
info: [decodingLevel=1] found JavaScript
info: file: saved /LABS/pdf-basics/samples/twitter2/c0610pall_MPA_Kit.re.pdf.maybe.vir to (./files/original_4b088c4be0c7bfca3ccbad187f97215d5fb1b181)
file: decoding_438f8880e0e100142aae652071590ba9ea2c572a: 2627 bytes
file: original_4b088c4be0c7bfca3ccbad187f97215d5fb1b181: 1406792 bytes
Talking to Mila from http://contagiodump.blogspot.com she pointed me to jsunpack result online http://jsunpack.jeek.org/dec/go?report=763c8312212dc379e18facb9d96815af36eb79ba .
Another things that pointed me that it a malicious file and I needed to figured out how to comprove was based on pdfid output :
PDFiD 0.0.11 c0610pall_MPA_Kit.re.pdf
PDF Header: %PDF-1.7
obj 60
endobj 60
stream 21
endstream 22
xref 2
trailer 2
startxref 2
/Page 1
/Encrypt 0
/ObjStm 2
/JS 1 /JavaScript 2
/AA 0
/OpenAction 0
/AcroForm 0
/JBIG2Decode 0
/RichMedia 0
/URI 2
/EmbeddedFile 0
/EmbeddedFiles 1
/cmd 0
/Action 0
/Launch 0
/Colors > 2^24 0
Based on that I started to test more in deep to try to make sure about this 0/43 result isn't a false negative or my research was generating a false positive
Analyzing JSunpack detection code I found
rule getAnnots: decodedPDF
{
meta:
impact = 3 //Since getAnnots may be legitimate
ref = "CVE-2009-1492"
hide = true
strings:
$cve20091492 = "getAnnots" nocase fullword
condition:
1 of them
}
That means that those alert didn't really mean that something is trying to exploit the flaw since getAnnots is a feature (not widely or common used) at PDF .
So @snowfl0w from http://contagiodump.blogspot.com pointed me to a very nice check website called https://www.vicheck.ca where I sent the sample and got the follow results:
=============================================
Thank you for your recent submission to vicheck.ca.
Date: 2010-07-15 18:59:54
Web submission from 187.105.222.250.
c0610pall_MPA_Kit.re.pdf:
EXECUTABLE SCAN: Javascript obfuscation syncAnnotScan to hide blocks (pdfexploit/full)
REPORT: https://www.vicheck.ca/md5query.php?hash=e40b33d95cb79765664d76e26d694efb
Confidence ranking: 75 (2 hits).
External hash searches:
VIRUS SCAN VirusTotal: 0/42 not detected
REPORT http://www.virustotal.com/analisis/10e735332a0bfb899a0a8ec83cb15f78915bf0a1fdbd311226f26e7501c5d766-1279207142
VIRUS SCAN Threat Expert: New
VIRUS SCAN Team-CYMRU.org: New
=============================================
As last test I sent it to joedoc.org and I got good results too
Joedoc (Beta) has detected the the following results:
Runtime detections:
- Successful exploit on Acrobat 9.2
- Successful exploit on Acrobat 9.0
- Successful exploit on Acrobat 8.1.2
- No exploit on Acrobat 7.0.5
Special thanks for @2gg and @snowfl0w
** About Virus Total it basically runs the sample against signatures and some AV protections have some behavior analysis among other tests that weren't realized against this sample.
Regards,
Rodrigo Montoro (Sp0oKeR)
http://spookerlabs.blogspot.com/2010/07/not-malicious-pdf-which-online-tool.html
Regards,
[suspicious:3] [PDF] c0610pall_MPA_Kit.re.pdf.maybe.vir
suspicious: getAnnots CVE-2009-1492 detected
info: [decodingLevel=0] JavaScript in PDF 1298 bytes, with 1329 bytes headers
info: [decodingLevel=1] found JavaScript
info: file: saved /LABS/pdf-basics/samples/twitter2/c0610pall_MPA_Kit.re.pdf.maybe.vir to (./files/original_4b088c4be0c7bfca3ccbad187f97215d5fb1b181)
file: decoding_438f8880e0e100142aae652071590ba9ea2c572a: 2627 bytes
file: original_4b088c4be0c7bfca3ccbad187f97215d5fb1b181: 1406792 bytes
- Successful exploit on Acrobat 9.0
Assinar:
Postagens (Atom)
