Thursday, May 25, 2023
3758 hash passwords
Attacks On PDF Certification
In recent years, we have presented How to Spoof PDF Signatures and Shadow Attacks: Hiding and Replacing Content in Signed PDFs, which describe attacks on PDF signatures under various attack scenarios. The attacks focused on so-called approval signatures. However, in addition to signing PDFs, the PDF specification also specifies the certification of documents, also known as certification signatures.
To close this research gap, we performed an extensive analysis of the security of PDF certification. In doing so, we developed the Evil Annotation Attack (EAA), as well as the Sneaky Signature Attack (SSA). The attack idea exploits the flexibility of PDF certification, which allows signing or adding annotations to certified documents under different permission levels. Our practical evaluation shows that an attacker could change the visible content in 15 of 26 viewer applications by using EAA and in 8 applications using SSA by using PDF specification compliant exploits. We improved both attacks' stealthiness with applications' implementation issues and found only two applications secure to all attacks.
PDF Structure and Basics
The PDF specification additionally defines interactive elements that allow user input into the document. Such elements are separated in two categories: forms and annotations.
Forms. PDF forms allow user input in a predefined mask, such as a text field, a radio button, or a selection box. Facilities, such as the administration, usually use forms to create PDF documents with predefined areas which are intended to be filled out by users. The user input is, however, limited to the defined form fields and cannot change other content within the PDF.
Annotations. Annotations introduce a different method for a user input by allowing a user to put remarks in a PDF document like text highlighting, strikeouts, or sticky notes. Annotations are not limited to predefined places within the PDF and can be applied everywhere within the document.
An Incremental Update introduces a possibility to extend a PDF by appending new information at the end of the file, see Inc. Update 1 in the figure above. In this way, the original document stays unmodified and a revision history of all document changes is kept. Each Incremental Update defines new objects, a new xref table, and a new trailer. An example of an Incremental Update is the inclusion of an certification, signature, annotation, or the filling out forms within a PDF.
UI-Layer 1: Top Bar Validation Status. UI-Layer 1 is usually displayed immediately after opening. Typical applications use a clearly visible bar on top of the PDF content. The status of the certification and signatures validation is provided as a text (e.g., valid/invalid), often combined with green, blue or red background colors, cf. figures in EAA and SSA sections.
Difference between Signed and Certified Documents
By signing a PDF document, a Signature object is created. This object contains the trusted public keys to verify the document, the signature value, the range of bytes that are protected by the signature, and a userfriendly information regarding the signer of the document. The Signature object is usually added to the PDF document by using an Incremental Update.
Certified Documents
P3: In addition to P2, annotations are also allowed.
Evil Annotation Attack (EAA)
Evaluating Permission P3. According to the specification, the following changes in a certified document with P3 are allowed: 1) adding/removing/modifying annotations, 2) fillingout forms, 3) and signing the document. We started with an in-depth analysis of all annotations and their features. We evaluated 28 different annotations and classified these with respect to their capabilities and danger level. The results are depicted in the Table on the right side and will be further explained.
Danger Level of Annotations. We determined three annotations with a danger level high capable to hide and add text and images: FreeText, Redact, and Stamp. All three can be used to stealthily modify a certified document and inject malicious content. In addition, 11 out of 28 annotations are classified as medium since an attacker can hide content within the certified document. The danger level of the remaining annotations is classified as low or none since such annotations are either quite limited or not allowed in certified documents.
Attacking with Annotations. According to our attacker model, the attacker possesses a validly certified document allowing the insertion of annotations. To execute the attack, the attacker modifies a certified document by including the annotation with the malicious content at a position of attacker's choice. Then, the attacker sends the modified file to the victim who verifies the digital signature. The victim could detect the attack if it manually opens UI-Layer 3 or clicks on the annotation. However, none of the tested PDF applications opened UI-Layer 3 automatically. Additionally, the attacker can lock an annotation to disable clicking on it.
Improving the stealthiness of EAA
Special Modifications
Sneaky Signature Attack (SSA)
The idea of the Sneaky Signature Attack (SSA) is to manipulate the appearance of arbitrary content within the PDF by adding overlaying signature elements to a PDF document that is certified at level P2.
Evaluating Permission P2. According to the specification, the following changes in a certified document with P2 are allowed: filling-out forms, and signing the document. We started the analysis of forms as depicted in the table on the right side and evaluated their capabilities.
Danger Level of Forms. According to our analysis, the danger level was none because the insertion of new form elements, customizing the font size and appearance, and removing form elements is prohibited. The only permitted change is on the value stored in the field. Thus, an attacker is not able to create forms which hide arbitrary content within the PDF document. Surprisingly, these restrictions are not valid for the signature field. By inserting a signature field, the signer can define the exact position of the field, and additionally its appearance and content. This flexibility is necessary since each new signature could contain the signer's information. The information can be a graphic, a text, or a combination of both. Nevertheless, the attacker can misuse the flexibility to stealthy manipulate the document and insert new content.
Attacking with Forms: SSA. The attacker modifies a certified document by including a signature field with the malicious content at a position of attacker's choice. The attacker then needs to sign the document, but he does not need to possess a trusted key. A self-signed certificate for SSA is sufficient. The only restriction is that the attacker needs to sign the document to insert the malicious signature field. This signing information can be seen by opening the PDF document and showing detailed information of the signature validation. In this case, the victim opening the file can get suspicious and refuse to accept the document, even though the certification is valid.
Improving the stealthiness of SSA
Evaluation
Authors of this Post
Vladislav Mladenov
Christian Mainka
Jörg Schwenk
Acknowledgments
Related articles
- Hack Apps
- Computer Hacker
- Hacker Tools Online
- Nsa Hacker Tools
- Pentest Tools Url Fuzzer
- Hacking Tools For Windows 7
- Pentest Tools For Android
- Hack And Tools
- Hacking Apps
- Hacker Tools Apk Download
- Tools For Hacker
- Hacker Tools For Windows
- Pentest Tools Website Vulnerability
- Hack Tools
- Github Hacking Tools
- Pentest Tools
- Hacking App
- Hack Tools For Pc
- Pentest Tools Download
- Pentest Tools Review
- Hack Tools
- Hacking Tools Free Download
- Hacking App
- Hacker Techniques Tools And Incident Handling
- Hacking Tools Hardware
- Pentest Tools For Mac
- Hacking Tools And Software
- Free Pentest Tools For Windows
- Hak5 Tools
- Hack Tools
- Tools For Hacker
- Pentest Tools Url Fuzzer
- Hacker Tools For Ios
- Hacker Tools Software
- Pentest Tools Android
- Pentest Tools For Windows
- Hack And Tools
- Hack Tools For Mac
- Hacking Apps
- Pentest Tools For Ubuntu
- Hacking Tools Kit
- Hack Tools For Mac
- Usb Pentest Tools
- Hack Tools Mac
- Free Pentest Tools For Windows
- Best Hacking Tools 2020
- Pentest Tools Kali Linux
- How To Install Pentest Tools In Ubuntu
- What Is Hacking Tools
- Hacking Tools 2019
- Hacking Tools For Beginners
- Hack Rom Tools
- Hacking Tools Free Download
- Hacking Tools For Beginners
- Nsa Hack Tools
- Hacking Tools 2019
- Hacking Tools Mac
- Black Hat Hacker Tools
- Hacker Search Tools
- Hack Tools For Windows
- Pentest Tools Download
- Pentest Tools Free
- Tools Used For Hacking
- Hacker Tools Github
- Termux Hacking Tools 2019
- Hack Tools Online
- Beginner Hacker Tools
People Of Frictional: Alex Camilleri
WHO AM I
Hi, my name is Alex and I am one of those people on this planet who make games for a living. I joined Frictional Games almost a year ago as a gameplay programmer & designer, and I am currently working on [REDACTED].
Despite my warm Sicilian blood, I ended up living in this beautiful yet terribly cold place called Sweden, where I obviously work from.
BACKGROUND
I got exposed to videogames as a kid, watching my dad playing Lucas adventures (that Indiana Jones and the Fate of Atlantis intro sequence will forever be impressed in my memory) and – like most people these days – I just spent a lot of my free time playing games.
I remember that when I was really really young I would draw labyrinths on paper and let my best friend play them as I was adding moving traps and enemies on the go. It was a complete nonsense but I think it's the earliest somewhat-interactive thing I've ever made. It was pretty fun.
During my teenage years it was really clear to me that I wanted to work with games, so I started doing game journalism and with two friends of mine I would spend nights playing games but also making terrible prototypes, studying some programming in our spare time. My first playable game was obviously an extremely generic shoot-em-up with horrible graphics and some keygen music slapped on top.
I eventually decided to move to the Netherlands to study and get my bachelor's degree in Game Design and Production. Living there was a great fun and allowed me to be part of an active gamedev community. I went to gamedev events, met many developers, expanded my network and opened my one-man-company called Kalopsia (hi Josh Homme!). I also joined a lot of game jams, one of which landed me an internship at Guerrilla Cambridge doing some level design on RIGS: Mechanized Combat League for PSVR (at the time the Morpheus prototype was just a bunch of lenses and cables put together with tape).
I ultimately started my own small but very personal project called Memoir En Code: Reissue, which I eventually released on Steam/Humble/GOG (totally not a plug). I worked solo on that project for quite some time, and after the release I felt the need to change gears and work in a team again. A friend of mine told me there was an opening at Frictional Games, and how could I not apply to the company that made SOMA?
Fun fact: after I submitted the work test I travelled to San Francisco for GDC17, and Thomas and Fredrik were there as well. We did not meet in person though, and I ended up spending most of the conference thinking about the test; it was actually a bit stressful and distracting! I found a partner for a new solo project that I was planning to make in case stuff didn't work out, but I got a positive response from Frictional and I obviously agreed to join the team.
I'm not crazy after all.
WHAT I DO
During the first weeks at Frictional I spent my time learning the tools and the overall work pipeline. This resulted in me creating a short psychedelic game where you put out fires by peeing on them, while Slayer music plays in the background. It's probably the best thing I have made to this date.
At the beginning there was a lot of stuff to learn and take in. But to be honest that was the entire point why I pushed myself into a new environment; you can't really become a better developer if you don't expose yourself to new stuff.
After I was done with the intro tasks I quickly jumped into production, working with Aaron (we are officially called the A-Team). He works from the UK, but we have a very clear line of communication; we are fairly independent, but we are always in sync, which is working out very well for us.
I spend most of my days scripting events, moving a door 0.25 units to the left to improve visibility and making that sound play with 0.5s delay because it just feels a bit better. The rest of the day is spent drinking tea with my desk-buddy Max and mostly hoping that nothing breaks. I have also spent some time making small changes to the debug tools we use, just to make the pipeline a bit smoother or a bit more comfortable. I juggle between working from the office and from home, depending on the amount of isolation my brain needs. Being able to do that is a big privilege that has a very positive creative impact on me.
![]() |
| Figure 2: my workstation at home. I have the same desk at the office and the same type of chaos ruling over it. |
STUFF THAT I LIKE
Since designing games is a complete dream-job, I try to keep myself busy by doing other creative things on the side. I spend quite some time doing photography, which I enjoy quite a lot. When I travel I always bring my a7ii with me, practicing and slowly improving over time. Aside from that, I also very much enjoy making music. Some months ago I got a Teenage Engineering OP-1 which I am having tons of fun with, and I am now playing a bit of ukulele.
I guess I won't be happy if I don't mention my biggest love. I have a deep (and almost unhealthy) love for anything Kojima makes. Over the years my love for his games went a bit overboard (I am the person behind the Metal Gear Timeline which you should totally check out if you are new to the saga) and now I ended up with a corner of my apartment being completely dedicated to his work. I keep adding stuff to the cabinet and now I probably need a new one after I got some new loot from my recent trip to Hong Kong. I fill my existential void with Metal Gear stuff, I need a doctor.
Oh, and you can find me on Twitter as @AlexKalopsia!
![]() |
| Figure 3: My babies. |
Wanna see who else works at Frictional? Check out the rest of the People of Frictional posts!
Monday, May 8, 2023
<> SEO Max to improve ranks in 30 days <>
Get a powerful SEO Boost with our all in one SEO MAX Package and beat your
competition within just 1 month
Whitehat SEO plan, check out more details here
https://www.creative-digital.co/product/seo-max-package/
thanks and regards
Creative Digital
Unsubscribe:
https://mgdots.co/unsubscribe/
Saturday, February 4, 2023
<> Semrush backlinks <>
Having links from dead domains towards your website, is of no use. NONE !
Here you will get backlinks from established domains, which have tons of
ranking keywords
check out more details:
https://www.creative-digital.co/product/semrush-backlinks/
thanks and regards
Creative Digital
Unsubscribe:
https://mgdots.co/unsubscribe/





