Deconstructing a Sexploitation Attack
rethinksecurity.io
rethinksecurity.io
Also be thoughtful about the trust you put into who you share any data with (especially photos) and be conscious about who can see it (this is a big deal on social media, where privacy and visibility permissions aren’t easily understood or used by people). Unless you’re a celebrity (and sometimes even if you’re a celebrity), sensitive information could leak from anyone you’ve shared it with.
Are PDFs as attack vectors common?
Fun times: https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...
Adobe acrobat is infamous for being infested with vulnerabilities.
(But yes, PDFs support scripting)
PDFs on the other hand are tetris complete.
Sadly this is how most attacks against {file formats, protocols, standards} work.
- Lots of parts of the Unicode spec (LTR/RTL swap, phishing attacks with homographs)
- Interpretation of character set by browser+server
- XML External Entities to do XXE
- YAML references to create YAMLBombs
- Zip massive compression ratios to create ZIP bombs
- JWT where user assigns no encryption algorithm
- PHP accepting URLs from user then piping them to PHP filters
- file upload with polymorphic files
- file upload where filename suffix doesn't match magic bytes
> Are PDFs as attack vectors common?This is not news. PDF-based attacks against Acrobat / Acrobat Reader, FoxIt, etc have been common for over a decade.
> Files based on Reader were exploited in almost 49 per cent of the targeted attacks of 2009[1]
> According to a newly released report by Symantec's MessageLabs, malicious PDF files outpace the distribution of related malicious attachments used in targeted attacks.[2] (2011)
> JavaScript and XFA Forms / Adobe LifeCycle[3]
[1] https://www.schneier.com/blog/archives/2010/03/pdf_the_most_...
[2] https://www.zdnet.com/article/report-malicious-pdf-files-bec...
[3] https://www.sentinelone.com/blog/malicious-pdfs-revealing-te...
This is literally the entire article on mobile safari
EDIT: purify ad-blocker caused the issue