<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacking with Browser Plugins</title>
	<atom:link href="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/feed" rel="self" type="application/rss+xml" />
	<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</link>
	<description>Blog of Sven Vetsch / Disenchant</description>
	<lastBuildDate>Tue, 02 Mar 2010 12:16:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Rajesh</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-146471</link>
		<dc:creator>Rajesh</dc:creator>
		<pubDate>Sun, 14 Sep 2008 04:11:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-146471</guid>
		<description>nice article....i really like ur site....
http://rajeshhackingarticles.blogspot.com</description>
		<content:encoded><![CDATA[<p>nice article&#8230;.i really like ur site&#8230;.<br />
<a href="http://rajeshhackingarticles.blogspot.com" rel="nofollow">http://rajeshhackingarticles.blogspot.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Disenchant</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-10021</link>
		<dc:creator>Disenchant</dc:creator>
		<pubDate>Fri, 20 Apr 2007 23:47:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-10021</guid>
		<description>Hi Scott,
yes it&#039;s correct that it won&#039;t work with Adobe Reader 8.0 because the issue was patched there :)</description>
		<content:encoded><![CDATA[<p>Hi Scott,<br />
yes it&#8217;s correct that it won&#8217;t work with Adobe Reader 8.0 because the issue was patched there <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-9751</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Thu, 19 Apr 2007 06:58:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-9751</guid>
		<description>Now I have yet another reason not to use the PDF plugin in Firefox.

I&#039;ve got Adobe Reader 8 set to view PDFs in the app and not in the browser.
I&#039;ve set Firefox to download PDFs and not to view them with the plugin.
And on top of all that, I use the PDF Download extension ( https://addons.mozilla.org/en-US/firefox/addon/636 ).

I could not reproduce the examples you&#039;ve given here.</description>
		<content:encoded><![CDATA[<p>Now I have yet another reason not to use the PDF plugin in Firefox.</p>
<p>I&#8217;ve got Adobe Reader 8 set to view PDFs in the app and not in the browser.<br />
I&#8217;ve set Firefox to download PDFs and not to view them with the plugin.<br />
And on top of all that, I use the PDF Download extension ( <a href="https://addons.mozilla.org/en-US/firefox/addon/636" rel="nofollow">https://addons.mozilla.org/en-US/firefox/addon/636</a> ).</p>
<p>I could not reproduce the examples you&#8217;ve given here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The show must go on at Disenchant&#8217;s Blog</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-3568</link>
		<dc:creator>The show must go on at Disenchant&#8217;s Blog</dc:creator>
		<pubDate>Thu, 01 Mar 2007 08:35:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-3568</guid>
		<description>[...] pdp wrote an interesting blog posting today about his research on the well known so called PDF UXSS vulnerability. Because pdp did a good job on his posting, I just want to quote a part of it: [...]</description>
		<content:encoded><![CDATA[<p>[...] pdp wrote an interesting blog posting today about his research on the well known so called PDF UXSS vulnerability. Because pdp did a good job on his posting, I just want to quote a part of it: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SSL Links - SSL Information &#187; Many Intruders Remain Unpredictable</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1278</link>
		<dc:creator>SSL Links - SSL Information &#187; Many Intruders Remain Unpredictable</dc:creator>
		<pubDate>Thu, 11 Jan 2007 05:56:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1278</guid>
		<description>[...] Who would have thought to abuse a .pdf viewer in such a manner? Read more about the problem here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Who would have thought to abuse a .pdf viewer in such a manner? Read more about the problem here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: deaz&#8217;s blog &#187; Browser plugins, PDF &#38; XSS</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1124</link>
		<dc:creator>deaz&#8217;s blog &#187; Browser plugins, PDF &#38; XSS</dc:creator>
		<pubDate>Fri, 05 Jan 2007 07:39:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1124</guid>
		<description>[...] http://www.disenchant.ch/blog/hacking-with-browser-plugins/34  Auch! Im not gonna try and prevent me from such thing&#8230; just uninstall adobe reader, not a big fan of it either ;) [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.disenchant.ch/blog/hacking-with-browser-plugins/34" rel="nofollow">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34</a>  Auch! Im not gonna try and prevent me from such thing&#8230; just uninstall adobe reader, not a big fan of it either ;) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: benny</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1121</link>
		<dc:creator>benny</dc:creator>
		<pubDate>Fri, 05 Jan 2007 02:41:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1121</guid>
		<description>may it help to deliver the pdf as application/zipor something else (to force the download)?
e.g. (apache)

    ForceType application/zip
 </description>
		<content:encoded><![CDATA[<p>may it help to deliver the pdf as application/zipor something else (to force the download)?<br />
e.g. (apache)</p>
<p>    ForceType application/zip</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: darron</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1120</link>
		<dc:creator>darron</dc:creator>
		<pubDate>Fri, 05 Jan 2007 02:09:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1120</guid>
		<description>What about forcing the PDF to download? Kind of like &lt;a href=&quot;http://technocrati.ca/2007/01/04/pretty-simple-fix-for-the-recent-acrobat-pdf-vulnerability/&quot; rel=&quot;nofollow&quot;&gt;this?&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>What about forcing the PDF to download? Kind of like <a href="http://technocrati.ca/2007/01/04/pretty-simple-fix-for-the-recent-acrobat-pdf-vulnerability/" rel="nofollow">this?</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thought Torrent - Protecting against PDF XSS with Apache</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1111</link>
		<dc:creator>Thought Torrent - Protecting against PDF XSS with Apache</dc:creator>
		<pubDate>Thu, 04 Jan 2007 19:17:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1111</guid>
		<description>[...] Recent EntriesFriendsArchiveUser Infoatrus.org - it&#039;s just not done   Protecting against PDF XSS with Apache&#171; previous entry &#124; next entry &#187;Jan. 4th, 2007 &#124; 05:11 amThis lovely article points out that you can execute Javascript from a PDF using a feature of Adobe&#039;s Acrobat Reader plugin. Filtering based on URLs (e.g. using mod_rewrite) won&#039;t work because the fragment section of a URL is not usually sent to the server.If the cookies for a site are restricted to exact name matches, then simply relocating all pdfs (and pdf-generating scripts/applications) to their own subdomain (e.g. pdfs.foo.com) is sufficient. Otherwise, you&#039;re stuck buying another domain (foopdfs.com) or doing something below.Another simple solution is to just make the browser download the pdf instead of trying to display it inline. This sucks for everyone not using a vulnerable version of the Adobe Acrobat Reader plugin, but it does work.For Apache 1.3, you can use mod_headers with a FileMatch directive to automatically handle your usual flat files.&lt;FilesMatch &quot;.pdf$&quot;&gt; Header set Content-Disposition attachment&lt;/FilesMatch&gt;Applications will need to be patched, of course.With Apache 2.0, you can use AddOutputFilterByType plus my newly-born mod_forcedl to do a more thorough job. Since this looks at the MIME type, it will even catch stuff generated by web applications.The more complex solution is to use JavaScript to scan the plugins (window.navigator.plugins), issue a user-specific token (random string), then refresh/redirect. On the server-side, you give the check page if a valid token isn&#039;t present (or, say, the User-Agent says it&#039;s wget) or serves up the pdf if the token checks out.(via evan_tech) [...]</description>
		<content:encoded><![CDATA[<p>[...] Recent EntriesFriendsArchiveUser Infoatrus.org &#8211; it&#39;s just not done   Protecting against PDF XSS with Apache&laquo; previous entry | next entry &raquo;Jan. 4th, 2007 | 05:11 amThis lovely article points out that you can execute Javascript from a PDF using a feature of Adobe&#8217;s Acrobat Reader plugin. Filtering based on URLs (e.g. using mod_rewrite) won&#8217;t work because the fragment section of a URL is not usually sent to the server.If the cookies for a site are restricted to exact name matches, then simply relocating all pdfs (and pdf-generating scripts/applications) to their own subdomain (e.g. pdfs.foo.com) is sufficient. Otherwise, you&#8217;re stuck buying another domain (foopdfs.com) or doing something below.Another simple solution is to just make the browser download the pdf instead of trying to display it inline. This sucks for everyone not using a vulnerable version of the Adobe Acrobat Reader plugin, but it does work.For Apache 1.3, you can use mod_headers with a FileMatch directive to automatically handle your usual flat files.&lt;FilesMatch &#8220;.pdf$&#8221;&gt; Header set Content-Disposition attachment&lt;/FilesMatch&gt;Applications will need to be patched, of course.With Apache 2.0, you can use AddOutputFilterByType plus my newly-born mod_forcedl to do a more thorough job. Since this looks at the MIME type, it will even catch stuff generated by web applications.The more complex solution is to use JavaScript to scan the plugins (window.navigator.plugins), issue a user-specific token (random string), then refresh/redirect. On the server-side, you give the check page if a valid token isn&#8217;t present (or, say, the User-Agent says it&#8217;s wget) or serves up the pdf if the token checks out.(via evan_tech) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TheHorse13</title>
		<link>http://www.disenchant.ch/blog/hacking-with-browser-plugins/34/comment-page-1#comment-1105</link>
		<dc:creator>TheHorse13</dc:creator>
		<pubDate>Thu, 04 Jan 2007 16:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/hacking-with-browser-plugins/34#comment-1105</guid>
		<description>This also does not work with IE7 with acrobat 7 plugin. It clips the java alert window.</description>
		<content:encoded><![CDATA[<p>This also does not work with IE7 with acrobat 7 plugin. It clips the java alert window.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
