際際滷

際際滷Share a Scribd company logo
Didier@DidierStevens.com
Penetration Document Format
Didier@DidierStevens.com
Didier@DidierStevens.com
Didier@DidierStevens.com
Identification and Analysis
Didier@DidierStevens.com
Didier@DidierStevens.com
PDFiD 0.0.9 hello-world.pdf
PDF Header: %PDF-1.1
obj 7
endobj 7
stream 1
endstream 1
xref 1
trailer 1
startxref 1
/Page 1
/Encrypt 0
/ObjStm 0
/JS 0
/JavaScript 0
/AA 0
/OpenAction 0
/AcroForm 0
/JBIG2Decode 0
/RichMedia 0
/Colors > 2^24 0
PDFiD
Didier@DidierStevens.com
/Name Obfuscation
Didier@DidierStevens.com
PDFiD Demo
Didier@DidierStevens.com
http://www.Virustotal.com
Didier@DidierStevens.com
Didier@DidierStevens.com
http://blog.rootshell.be
Didier@DidierStevens.com
In-The-Wild PDF
Didier@DidierStevens.com
PoC Pure ASCII PDF
Didier@DidierStevens.com
pdf-parser Demo
Didier@DidierStevens.com
Protection
Didier@DidierStevens.com
Foxit Reader
Didier@DidierStevens.com
Sumatra PDF
Didier@DidierStevens.com
Know Your Enemy ...
Didier@DidierStevens.com
Disable JavaScript?
Didier@DidierStevens.com
 Find His Achilles Heel
Didier@DidierStevens.com
Access Tokens
Didier@DidierStevens.com
Use Restricted Tokens
 Windows >= Vista + UAC
 DropMyRights
 StripMyRights
 SAFER SRP
Didier@DidierStevens.com
Restricted Token in Action
Didier@DidierStevens.com
Disclosure CVE-2009-2979
Didier@DidierStevens.com
XML-Bomb in Metadata
Didier@DidierStevens.com
Questions?
And hopefully some answers...
Didier@DidierStevens.com
Thank you
http://blog.DidierStevens.com

More Related Content

Viewers also liked (15)

Plafons colonies la sinia
Plafons colonies la sinia Plafons colonies la sinia
Plafons colonies la sinia
meganuke94
8. jes炭s mostraba simpat鱈a8. jes炭s mostraba simpat鱈a
8. jes炭s mostraba simpat鱈a
A L
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
Event-agency C4group
Chimney & Flue Systems MF BrocureChimney & Flue Systems MF Brocure
Chimney & Flue Systems MF Brocure
Airtherm Engineering
Rachel Fullmer-portfolio
Rachel Fullmer-portfolioRachel Fullmer-portfolio
Rachel Fullmer-portfolio
skeez0526
2. crisis en el ed辿n2. crisis en el ed辿n
2. crisis en el ed辿n
A L
Coal train fact_check
Coal train fact_checkCoal train fact_check
Coal train fact_check
BentonFranklin
Spyddr
SpyddrSpyddr
Spyddr
Steph Cliche
Cf 8 blocks of success training1
Cf 8 blocks of success training1Cf 8 blocks of success training1
Cf 8 blocks of success training1
Muhammed Eid
flue dilution solution
 flue dilution solution  flue dilution solution
flue dilution solution
Airtherm Engineering
12. los 炭ltimos d鱈as de jes炭s12. los 炭ltimos d鱈as de jes炭s
12. los 炭ltimos d鱈as de jes炭s
A L
WordPress 3.6 New Features
WordPress 3.6 New FeaturesWordPress 3.6 New Features
WordPress 3.6 New Features
masmanx
76216 99253-1-pb76216 99253-1-pb
76216 99253-1-pb
Rolando Calle
Social Media for Business
Social Media for BusinessSocial Media for Business
Social Media for Business
Deborah Deras, M.S., ALSP
The busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterestThe busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterest
BestsellerSociety
Plafons colonies la sinia
Plafons colonies la sinia Plafons colonies la sinia
Plafons colonies la sinia
meganuke94
8. jes炭s mostraba simpat鱈a8. jes炭s mostraba simpat鱈a
8. jes炭s mostraba simpat鱈a
A L
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
亠仍仂仗仂从舒 于 仗舒从亠 "弌仂从仂仍仆亳从亳"
Event-agency C4group
Chimney & Flue Systems MF BrocureChimney & Flue Systems MF Brocure
Chimney & Flue Systems MF Brocure
Airtherm Engineering
Rachel Fullmer-portfolio
Rachel Fullmer-portfolioRachel Fullmer-portfolio
Rachel Fullmer-portfolio
skeez0526
2. crisis en el ed辿n2. crisis en el ed辿n
2. crisis en el ed辿n
A L
Coal train fact_check
Coal train fact_checkCoal train fact_check
Coal train fact_check
BentonFranklin
Cf 8 blocks of success training1
Cf 8 blocks of success training1Cf 8 blocks of success training1
Cf 8 blocks of success training1
Muhammed Eid
12. los 炭ltimos d鱈as de jes炭s12. los 炭ltimos d鱈as de jes炭s
12. los 炭ltimos d鱈as de jes炭s
A L
WordPress 3.6 New Features
WordPress 3.6 New FeaturesWordPress 3.6 New Features
WordPress 3.6 New Features
masmanx
76216 99253-1-pb76216 99253-1-pb
76216 99253-1-pb
Rolando Calle
The busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterestThe busy author's guide to popularity and profit on pinterest
The busy author's guide to popularity and profit on pinterest
BestsellerSociety

More from Steph Cliche (20)

Spy pack
Spy packSpy pack
Spy pack
Steph Cliche
Sc2014 proceedings
Sc2014 proceedingsSc2014 proceedings
Sc2014 proceedings
Steph Cliche
Satellite hacking
Satellite hackingSatellite hacking
Satellite hacking
Steph Cliche
Safes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locksSafes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locks
Steph Cliche
Ieee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systemsIeee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systems
Steph Cliche
Ieee interference-measurements-802.11n
Ieee interference-measurements-802.11nIeee interference-measurements-802.11n
Ieee interference-measurements-802.11n
Steph Cliche
Guardi final report
Guardi final reportGuardi final report
Guardi final report
Steph Cliche
718001 000 en
718001 000 en718001 000 en
718001 000 en
Steph Cliche
2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata
Steph Cliche
Tmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hackluTmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hacklu
Steph Cliche
Public wifi
Public wifiPublic wifi
Public wifi
Steph Cliche
Le petit livre_du_hacker_2013Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013
Steph Cliche
013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e
Steph Cliche
Hack.lu 09 ip-morph
Hack.lu 09 ip-morphHack.lu 09 ip-morph
Hack.lu 09 ip-morph
Steph Cliche
12
1212
12
Steph Cliche
09 09 2014
09 09 201409 09 2014
09 09 2014
Steph Cliche
7 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.07 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.0
Steph Cliche
Global maritime-security
Global maritime-securityGlobal maritime-security
Global maritime-security
Steph Cliche
Future war
Future warFuture war
Future war
Steph Cliche
Sc2014 proceedings
Sc2014 proceedingsSc2014 proceedings
Sc2014 proceedings
Steph Cliche
Satellite hacking
Satellite hackingSatellite hacking
Satellite hacking
Steph Cliche
Safes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locksSafes locking device-_mechanical_locks_versus_electronic_locks
Safes locking device-_mechanical_locks_versus_electronic_locks
Steph Cliche
Ieee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systemsIeee project-2014-2015-context-based-access-control-systems
Ieee project-2014-2015-context-based-access-control-systems
Steph Cliche
Ieee interference-measurements-802.11n
Ieee interference-measurements-802.11nIeee interference-measurements-802.11n
Ieee interference-measurements-802.11n
Steph Cliche
Guardi final report
Guardi final reportGuardi final report
Guardi final report
Steph Cliche
2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata2010 12-03 a-lawyers_guidetodata
2010 12-03 a-lawyers_guidetodata
Steph Cliche
Tmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hackluTmplab hostile wrt-5-hacklu
Tmplab hostile wrt-5-hacklu
Steph Cliche
Le petit livre_du_hacker_2013Le petit livre_du_hacker_2013
Le petit livre_du_hacker_2013
Steph Cliche
013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e013 50001-001 spy-elite_operators_manual_rev_e
013 50001-001 spy-elite_operators_manual_rev_e
Steph Cliche
Hack.lu 09 ip-morph
Hack.lu 09 ip-morphHack.lu 09 ip-morph
Hack.lu 09 ip-morph
Steph Cliche
7 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.07 1-system plus-evolution_spares_eng_6.0
7 1-system plus-evolution_spares_eng_6.0
Steph Cliche
Global maritime-security
Global maritime-securityGlobal maritime-security
Global maritime-security
Steph Cliche

Penetration document format slides