Hiding Malicious Content in PDF Documents

Hiding Malicious Content in PDF Documents
复制标题

隐藏 PDF 文档中的恶意内容

DOI:
--
复制
发表时间:
2011
期刊:
arXiv.org
影响因子:
--
通讯作者:
Dan
Dan
中科院分区:
--
文献类型:
--
作者:
Dan

文献摘要

被引文献

相似文献

本文是针对特定数字签名漏洞的概念验证演示,该漏洞表明了Wysiwys的无效性(您看到的是您的标志)概念。该算法非常简单:攻击者生成一个具有两种不同类型的内容(例如,作为PDF文档)的多态文件,以及图像:TIFF-两种最广泛使用的文件格式)。当受害人签署双内容文件时,他/她只看到一个PDF文档,并且不知道文件中的隐藏内容。从受害者那里获得合法签名的文件后,攻击者只需将扩展名更改为其他文件格式即可。由于没有更改,这不会使数字签名无效。攻击的破坏性潜力是相当大的,因为便携式文档格式(PDF)广泛用于电子政务和电子商务环境中。
This paper is a proof-of-concept demonstration for a specific digital signatures vulnerability that shows the ineffectiveness of the WYSIWYS (What You See Is What You Sign) concept. The algorithm is fairly simple: the attacker generates a polymorphic file that has two different types of content (text, as a PDF document for example, and image: TIFF - two of the most widely used file formats). When the victim signs the dual content file, he/ she only sees a PDF document and is unaware of the hidden content inside the file. After obtaining the legally signed document from the victim, the attacker simply has to change the extension to the other file format. This will not invalidate the digital signature, as no bits were altered. The destructive potential of the attack is considerable, as the Portable Document Format (PDF) is widely used in e-government and in e-business contexts.