<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The PDF is &amp;quot;Broken&amp;quot; in Threats</title>
    <link>https://community.isc2.org/t5/Threats/The-PDF-is-quot-Broken-quot/m-p/43138#M270</link>
    <description>&lt;P&gt;Not the same thing, but this takes me back to 2008/9 when Adobe applications took over as the literal soft inviting underbelly of Windows as better coding, DEP, ASLR etc started to bite.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a memo from an authority requiring that we uninstall Acrobat and Acrobat Reader or, accept the risk. Naturally the implications were assessed, and risk was duly accepted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m glad to say I haven’t seen Acrobat anywhere for some time... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Feb 2021 16:08:37 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2021-02-08T16:08:37Z</dc:date>
    <item>
      <title>The PDF is "Broken"</title>
      <link>https://community.isc2.org/t5/Threats/The-PDF-is-quot-Broken-quot/m-p/43115#M259</link>
      <description>&lt;P&gt;Next time you open a PDF and nothing displays think again, you may have just be pawned into running a webserver.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P&lt;SPAN&gt;DF is at its core a container format that lets you encode arbitrary binary blobs that don’t even have to contribute to the document’s rendering. And those blobs can be stacked with an arbitrary number of encodings, some of which are bespoke features of PDF.&amp;nbsp;To learn more about the threat check out "&lt;A href="https://blog.trailofbits.com/2021/02/02/pdf-is-broken-a-justctf-challenge/" target="_blank" rel="noopener"&gt;PDF is Broken: a justCTF Challenge&lt;/A&gt;".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:47:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/The-PDF-is-quot-Broken-quot/m-p/43115#M259</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: The PDF is "Broken"</title>
      <link>https://community.isc2.org/t5/Threats/The-PDF-is-quot-Broken-quot/m-p/43138#M270</link>
      <description>&lt;P&gt;Not the same thing, but this takes me back to 2008/9 when Adobe applications took over as the literal soft inviting underbelly of Windows as better coding, DEP, ASLR etc started to bite.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a memo from an authority requiring that we uninstall Acrobat and Acrobat Reader or, accept the risk. Naturally the implications were assessed, and risk was duly accepted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m glad to say I haven’t seen Acrobat anywhere for some time... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 16:08:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/The-PDF-is-quot-Broken-quot/m-p/43138#M270</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2021-02-08T16:08:37Z</dc:date>
    </item>
  </channel>
</rss>

