penetration document format
play

Penetration Document Format Didier@DidierStevens.com - PowerPoint PPT Presentation

Penetration Document Format Didier@DidierStevens.com Didier@DidierStevens.com Didier@DidierStevens.com Identification and Analysis Didier@DidierStevens.com Didier@DidierStevens.com PDFiD PDFiD 0.0.9 hello-world.pdf PDF Header: %PDF-1.1 obj


  1. Penetration Document Format Didier@DidierStevens.com

  2. Didier@DidierStevens.com

  3. Didier@DidierStevens.com

  4. Identification and Analysis Didier@DidierStevens.com

  5. Didier@DidierStevens.com

  6. PDFiD PDFiD 0.0.9 hello-world.pdf PDF Header: %PDF-1.1 obj 7 endobj 7 stream 1 endstream 1 xref 1 trailer 1 startxref 1 /Page 1 /Encrypt 0 /ObjStm 0 /JS 0 /JavaScript 0 /AA 0 /OpenAction 0 /AcroForm 0 /JBIG2Decode 0 /RichMedia 0 /Colors > 2^24 0 Didier@DidierStevens.com

  7. /Name Obfuscation Didier@DidierStevens.com

  8. PDFiD Demo Didier@DidierStevens.com

  9. http://www.Virustotal.com Didier@DidierStevens.com

  10. Didier@DidierStevens.com

  11. http://blog.rootshell.be Didier@DidierStevens.com

  12. In-The-Wild PDF Didier@DidierStevens.com

  13. PoC Pure ASCII PDF Didier@DidierStevens.com

  14. pdf-parser Demo Didier@DidierStevens.com

  15. Protection Didier@DidierStevens.com

  16. Foxit Reader Didier@DidierStevens.com

  17. Sumatra PDF Didier@DidierStevens.com

  18. Know Your Enemy ... Didier@DidierStevens.com

  19. Disable JavaScript? Didier@DidierStevens.com

  20. … Find His Achilles Heel Didier@DidierStevens.com

  21. Access Tokens Didier@DidierStevens.com

  22. Use Restricted Tokens ● Windows >= Vista + UAC ● DropMyRights ● StripMyRights ● SAFER SRP Didier@DidierStevens.com

  23. Restricted Token in Action Didier@DidierStevens.com

  24. Disclosure CVE-2009-2979 Didier@DidierStevens.com

  25. XML-Bomb in Metadata Didier@DidierStevens.com

  26. Questions? And hopefully some answers... Didier@DidierStevens.com

  27. Thank you http://blog.DidierStevens.com Didier@DidierStevens.com

Recommend


More recommend