DocuCrunch.com » PDFs are safe, right? Not anymore

PDFs are safe, right? Not anymore

July 27, 2010 by Steve Hannaford
Posted in: In this week's e-newsletter, Latest News & Views, Security

There’s something about PDF files that makes users think they’re safe to open. And that’s exactly why they’ve become one of the preferred malware delivery vehicles for hackers.

That’s the warning from Appligent Software CEO Duff Johnson, one of the experts on the file format and document management.

The worst thing is that most users and IT staff treat PDF files as somehow different from other files. Although they’re the most commonly used format for archiving and file sharing, PDF files are as capable of being corrupted with malware as damaging as found in the most pernicious spam or corrupt Office file.

This didn’t use to be the case, notes Johnson, but over the last few years, hackers have turned their attention to this widely used and seemingly safe format. He links to an IBM Threat Report that documents this growing problem.

According to some research, PDFs represent the biggest malware threat companies face right now. For example, a report by security firm ScanSafe found that in the fourth quarter of 2009, 80% of all exploits targeted flaws in Adobe’s PDF software. At the time, those flaws were getting a lot of attention, leading hackers to put more effort into exploiting them.

And earlier this year, we reported on another attack that didn’t make use of a security bug, but rather exploited PDF documents’ ability to run embedded executable files.

PDF attacks usually occur when users are tricked into opening a file, often one that uses embedded JavaScript or Flash content that interacts with a remote server.

Key steps for companies:

  1. IT departments have to get up to speed on the latest PDF threats, just as they keep current on e-mail threats.
  2. End users should learn to treat PDF files the same as any file — don’t open it if you are unsure of its origin.
  3. Update PostScript viewing software (generally Adobe Viewer) as soon as it is released — Adobe is constantly working on responding to the latest threats.
  4. Consider using alternative PDF viewers that are less common than Adobe, and therefore may be less susceptible to attacks.
  5. You may want to consider disabling Flash and JavaScript in your PDF readers. At least one major company surveyed said that they only permit JavaScript as an exception.
  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , ,


One Response to “PDFs are safe, right? Not anymore”

  1. Mark Welch Says:

    Why are people spreading such fear? What is the matter with creating PDF files that only contain formatted text and static image files? Why must everything be everything to everybody? Why can’t we have a simple solution in the public domain that does one thing efficiently? Then we wouldn’t have to worry about the latest security threat on the horizon.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement