الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

استغلال ملف Pdf بدون فتحه أو حتى لمسه

بدأه merouane في 12 مارس 2009 · 12 رد · 5,368 مشاهدة · في قسم أمن المعلومات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم و رحمة الله تعالى و بركاته

كيف يمكن استغلال إضافات البرامج الأكثر شعبية .. هذا ما أبرزه Didier Stevens في فيديو و أيضا مع الشرح في مدونته

Sometimes a piece of malware can execute without even opening the file. As this is the case with the /JBIG2Decode vulnerability in PDF documents, I took the time to produce a short video showing 3 ways the vulnerability can trigger without even opening the PDF document.

The first 2 demos use a “classic” /JBIG2Decode PDF exploit, the third demo uses a new PoC /JBIG2Decode PDF exploit I developed. This PDF document has a malformed /JBIG2Decode stream object in the metadata instead of the page. All PDF documents used have just a malformed /JBIG2Decode stream object, they don’t include a payload (shellcode), neither a JavaScript heap spray.

So how is it possible to exploit this vulnerability in a PDF document without having the user open this document? The answer lies in Windows Explorer Shell Extensions. Have you noticed that when you install a program like WinZip, an entry is added to the right-click menu to help you compress and extract files? This is done with a special program (a shell extension) installed by the WinZIp setup program.

When you install Adobe Acrobat Reader, a Column Handler Shell Extension is installed. A column handler is a special program (a COM object) that will provide Windows Explorer with additional data to display (in extra columns) for the file types the column handler supports. The PDF column handler adds a few extra columns, like the Title. When a PDF document is listed in a Windows Explorer windows, the PDF column handler shell extension will be called by Windows Explorer when it needs the additional column info. The PDF column handler will read the PDF document to extract the necessary info, like the Title, Author, …

This explains how the PDF vulnerability can be exploited without you opening the PDF document. Under the right circumstances, a Windows Explorer Shell Extension will read the PDF document to provide extra information, and in doing so, it will execute the buggy code and trigger the vulnerability. Just like it would when you would explicitly open the document. In fact, we could say that the document is opened implictly, because of your actions with Windows Explorer.

So let me demo 3 circumstances under which a PDF Shell Extension will act and thereby trigger the vulnerability. One important detail before I do this: when the exception occurs in the Adobe Acrobat code, it is trapped by Windows Explorer without any alert. That’s why in the demos, I attached a debugger (ODBG) to Windows Explorer to intercept and visualize this exception. So each time the vulnerability triggers, the view switches to the debugger to display the exception.

In the first demo, I just select the PDF document with one click. This is enough to exploit the vulnerability, because the PDF document is implicitly read to gather extra information.

In the second demo, I change the view to Thumbnails view. In a thumbnail view, the first page of a PDF document is rendered to be displayed in a thumbnail. Rendering the first page implies reading the PDF document, and hence triggering the vulnerability.

In the third demo, I use my special PDF document with the malformed stream object in the metadata. When I hover with the mouse cursor over the document (I don’t click), a tooltip will appear with the file properties and metadata. But with my specially crafted PDF document, the vulnerability is triggered because the metadata is read to display the tooltip…

So be very careful when you handle malicious files. You could execute it inadvertently, even without double-clicking the file. That’s why I always change the extension of malware (trojan.exe becomes trojan.exe.virus) and handle them in an isolated virus lab. Outside of that lab, I encrypt the malware.

المصدر: http://blog.didierstevens.com/2009/03/04/q...e-trigger-trio/

أيضا يوجد بهذه المدونة مواضيع أخرى تتعلق بملفات PDF .. الظاهر لديه مشكلة مع Adobe أو من فرط حبه لها :D

:)

#2

ممتاز، النسكافية جاءت في وقتها :D

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#3
Xacker كتب:
ممتاز، النسكافية جاءت في وقتها :D

ماذا ؟ لم أفهم ما المعنى

:)

#4

كنت للتو جئت وبيدي فنجان النسكافية فرأيت الموضوع :D

مفيدة للمدمنين :lol:

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#5

كنت أتصفح المقال الأخير الذي كتبه DS

مشكلة كبيرة!

My previous blogpost showed how minimal user interaction can still get a malicious PDF document to infect a machine. Remembering F-Secure’s misadventure with .WMF and Google Desktop Search, I took some time to look at Windows Indexing Service. The news is not good. This time, I can get a PoC PDF document to trigger the /JBIG2Decode bug without any user interaction whatsoever. And the bug happens in a process running with Local System rights!

On a Windows XP SP2 machine with Windows Indexing Services started and Adobe Acrobat Reader 9.0 installed, there is absolutely no user interaction required to trigger the /JBIG2Decode vulnerability. When the PoC PDF file is on the disk, it will be indexed by Windows Indexing Services and the buggy /JBIG2Decode code will be executed.

When Adobe Acrobat Reader 9.0 is installed, it also installs an IFilter (AcroRdIF.dll). This COM object extends the Windows Indexing Service with the capability to read and index PDF documents. When the Windows Indexing Service encounters a PDF file, it will index it. The content indexing daemon (cidaemon.exe) calls the Acrobat IFilter (AcroRdIF.dll) which loads the Acrobat PDF parser (AcroRD32.dll). If the PDF document contains a malformed /JBIG2Decode stream object, it will result in an access violation in the instruction at 0×01A7D89A.

In other words, if you’ve a malicious PDF document on a machine with Windows Indexing Services, it can infect your machine. And you don’t need a user to open or select the PDF document.

The good news is that Windows Indexing Services is not started on a default Windows XP SP2 install. Update: Although Windows Indexing Services is not on by default, after you’ve executed a search as local admin, you’ll be asked if you want “to make future searches faster”. If you answer yes, Windows Indexing Services will be automatically started.

The bad news is that Windows Indexing Services runs under the local system account on Windows XP SP2. This results in a privilege escalation.

Consider a Windows machine with Windows Indexing Services running, Adobe Acrobat reader installed and a file sharing service (FTP/IIS/P2P/…). Uploading a specially crafted PDF document to this machine will give you a local system shell.

To disable Windows Indexing Services’ capability to index PDF documents, unregister the IFilter: regsvr32 /u AcroRdIf.dll

But IFilters are also used by other software:

* Microsoft Search Server 2008

* Windows Desktop Search

* SharePoint

* SQL Server (full-text search)

My PoC PDF file also triggers in /JBIG2Decode in Windows Desktop Search (I tested version 4.0). But Windows Desktop Search has a better security architecture than Windows Indexing Service. Although the service runs under the Local System account, the actual calling of the IFilters is done in a separate process that runs under the Local Service account (this account has less privileges and can’t take full control of the machine).

wds.png

I’ve not analyzed other applications using IFilters. If you use ScarePoint (that’s how my wife, who has to work with it, calls it) or another IFilter supporting application and you want to be safe, unregister the Acrobat IFilter.

And don’t forget that, depending on your Windows version and CPU, you’re also protected by technologies like DEP and ASLR.

Google Desktop Search doesn’t use IFilters, unless you’ve installed this plugin to add IFilter support to Google Desktop Search.

تم تعديل هذه المشاركة بواسطة Xacker في 13 مارس 2009 في 04:12

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#6

هذه المشكلة و التي سبقتها (بخصوص ملف PDF المعدَّل) .. كم من مضاد فيروس يتعرف عليها ؟

و لهذا أيضا حذفت الخدمة الجديدة للبحث - من طرف ميكروسوفت - من حاسوبي التي تحتاج إلى فهرسة "كل الملفات" على الهارد (يعمل مع بداية التشغيل و ياعيني على الذاكرة) - حذفته قبل قراءتي لهذه المقالة

:)

تم تعديل هذه المشاركة بواسطة merouane في 13 مارس 2009 في 07:24

#7

أيضا موضوع له علاقة و يحتوي أيضا على الحل، مع أن شركة Adobe قد أصدرت تحديثا بخصوص هذا الاستغلال

Adobe Reader and Acrobat JBIG2 buffer overflow vulnerability

Overview

Adobe Reader and Acrobat contain a buffer overflow vulnerability that may allow an attacker to execute arbitrary code.

I. Description

Adobe Acrobat Reader is software designed to view Portable Document Format (PDF) files. Adobe also distributes the Adobe Acrobat Plug-In to allow users to view PDF files inside of a web browser. Adobe Reader and Acrobat contain a buffer overflow vulnerability in the handling of JBIG2 streams.

Exploit code for this vulnerability is publicly available.

II. Impact

By convincing a user to open a malicious PDF file, an attacker may be able to execute code or cause a vulnerable PDF viewer to crash. The PDF could be emailed as an attachment or hosted on a website.

III. Solution

Apply an update

This issue is addressed in Adobe Reader and Acrobat versions 9.1. More details are available in Adobe Security Bulletin APSB09-03.

Disable JavaScript in Adobe Reader and Acrobat

Disabling Javascript may prevent this vulnerability from being exploited. Acrobat JavaScript can be disabled in the General preferences dialog (Edit -> Preferences -> JavaScript and un-check Enable Acrobat JavaScript). Note that this will not block the vulnerability. Adobe products still may crash when parsing specially crafted PDF documents. Disabling JavaScript will mitigate a common method used to achieve code execution with this vulnerability. Also note that when JavaScript is disabled in Adobe Reader, the software will prompt the user to enable JavaScript when it opens a document that uses the feature. So although JavaScript is a single click away, setting this preference can help mitigate exploits that use JavaScript. Some have reported that they have successfully achieved code execution without the use of JavaScript.

Some vendors ship javascript support in a seperate package. Removing this package may remove javascript support in the Adobe PDF reader.

Prevent Internet Explorer from automatically opening PDF documents

The installer for Adobe Reader and Acrobat configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to the safer option of prompting the user by importing the following as a .REG file:

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\AcroExch.Document.7]

"EditFlags"=hex:00,00,00,00

Disable the displaying of PDF documents in the web browser

Preventing PDF documents from opening inside a web browser may mitigate this vulnerability. If this workaround is applied to updated versions of the Adobe reader, it may mitigate future vulnerabilities.

To prevent PDF documents from automatically being opened in a web browser:

1. Open Adobe Acrobat Reader.

2. Open the Edit menu.

3. Choose the preferences option.

4. Choose the Internet section.

5. Un-check the "Display PDF in browser" check box.

Disable Adobe Acrobat Windows Shell integration

Adobe Acrobat and Reader integrates itself with the Windows shell. The file pdfshell.dll is used to configure Windows Explorer to launch Adobe components to render, preview, and obtain details from a PDF document, all without actually opening the PDF document itself. Windows Shell integration for Adobe Acrobat and Reader can be disabled by unregistering the pdfshell.dll by running the following command:

regsvr32 /u "%CommonProgramFiles%\Adobe\Acrobat\ActiveX\pdfshell.dll"

Disable the Adobe Acrobat Indexing Service filter

Adobe Reader and Adobe Acrobat install an Indexing Service filter that is used to parse PDF files. These filters are provided by AcroRdIF.dll and AcroIF.dll, respectively. When an application that uses the Adobe IFilters indexes a malicious PDF document, the vulnerability may be triggered. This attack vector can be mitigated by unregistering the Adobe IFilter files.

Adobe Acrobat users should locate the Acrobat directory and run: regsvr32 /u AcroIF.dll

Adobe Reader users should locate the Adobe Reader directory and run: regsvr32 /u AcroRdIF.dll

Do not access PDF documents from untrusted sources

Do not open unfamiliar or unexpected PDF documents, particularly those hosted on web sites or delivered as email attachments. Please see Cyber Security Tip ST04-010.

Systems Affected

Vendor Status Date Notified Date Updated

Adobe Vulnerable 2009-02-19 2009-03-11

References

http://www.us-cert.gov/cas/tips/ST04-010.html

http://www.cert.org/tech_tips/securing_browser/

http://www.adobe.com/support/security/advi.../apsa09-01.html

http://www.adobe.com/support/security/bull.../apsb09-03.html

http://www.avertlabs.com/research/blog/ind...-pdf-documents/

http://jbig2.com/

http://www.shadowserver.org/wiki/pmwiki.ph...lendar.20090219

http://www.shadowserver.org/wiki/pmwiki.ph...lendar.20090221

http://vrt-sourcefire.blogspot.com/2009/02...roreader-9.html

http://secunia.com/blog/44/

http://www.milw0rm.com/exploits/8090

Credit

Thanks to Adobe for information that was used in this report.

This document was written by Will Dormann and Ryan Giobbi.

Other Information

Date Public: 2009-02-19

Date First Published: 2009-02-20

Date Last Updated: 2009-03-11

CERT Advisory:

CVE-ID(s): CVE-2009-0658

NVD-ID(s): CVE-2009-0658

US-CERT Technical Alerts:

Metric: 32,91

Document Revision: 83

المصدر: http://www.kb.cert.org/vuls/id/905281

رابط الإعلان عن التحديث : http://www.adobe.com/support/security/bull.../apsb09-03.html

أقتبس منه جملة واحدة هي

اقتباس

Adobe is also in contact with anti-virus and security vendors, including McAfee, Symantec and others, on this issue in order to ensure the security of our mutual customers

ملاحظة بخصوص قراءة ملفPDF تلقائيا من طرف متصفح الأنترنت، الإضافة noscript ستمنع هذه العملية حتى توافق عليها.

:)

تم تعديل هذه المشاركة بواسطة merouane في 13 مارس 2009 في 20:06

#8

الترقيع إلى الآن موجه للإصدارات الأخيرة Acrobat 9 و Acrobat Reader 9

من المتوقع أن يتم طرح الترقيعات الخاصة بالإصدارات Adobe Reader 7 + 8, Acrobat 7 + 8 بتاريخ 18 آذار. "متوقع"

عندي شبكتي الآن علي فتح 20 جهاز من DF ثم تثبيت الترقيع ومن ثم إغلاقه مرة أخرى :wacko:

ناهيك عن أن الأجهزة فيها Pro Extended بالتالي حجم التحديث 119 ميغا :lol:

تم تعديل هذه المشاركة بواسطة Xacker في 13 مارس 2009 في 17:28

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#9

البارحة سهرت الليل لاستغلال الأنترنت (هذه الأيام صفحة كل دقيقتين) و بعد تحميل الترقيع - 119 ميغا - (و يا فرحتي) وجدت أنه غير موافق للإصدار (لدي Acrobat 9 pro)

و أحببت فقط ان أذكره لينتبه الأعضاء عند التحميل

:)

#10

Pro 9 extended متوافق مع ما لدي, 119 ميغا .. لكن ظهرت مشكلة أخرى... الـ license :lol:

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#11

هل يحدف licence أم يجددها؟

لو كنت مكانك لوفرت AcroReader في الحواسيب 20، لسببين : خفيف و مجاني

فإن كانت هناك أسباب أجهلها .. منك نستفيد

أمر آخر : ألا يمكنك القيام بالتحديث عبر الشبكة .. بحيث تنفذ التحديث في نفس الوقت؟

:)

#12

بالضبط لا أعلم لأني قمت بالترقيع بشكل سريع لواحد من الأجهزة بوجود DF حتى أتأكد أنه يعمل.

بعدما فتحت Adobe Acrobat Pro 9 Extended ونظرت إلى About للتأكد من رقم الإصدار ثم عدت للخروج فوجئت برسالة لم أعرها الكثير من الانتباه فلم أحفظها، تتعلق بموضوع اختلاف الترخيص أو ما شابه وعلي أن أعيد تسجيل البرنامج من جديد.

سأفيدك بها غداً لو أردت.

أما من ناحية التخلي عن النسخة Pro فكل ما في الأمر أني أفضل توفير أفضل product للمستخدم لدي فربما يحتاجه ولا أريد أن أقوم بتثبيت كامل النسخة فقط لأجله كما تعلم الحزمة وحدها حجمها 1GB وفك الضغط تقريباً المثل ثم تثبيت البرنامج المثل! المستخدم سيطفش :P - كوني في مقهى

أما بخصوص Extended فليست بذي أهمية، لكني قمت بتحميل هذه النسخة بالأساس لأنها تحوي على كامل حزمة Pro + Adobe Presenter والذي أعتقده تطبيق جيد من النظرة الأولى للغرض الذي صمم لأجله.

اقتباس
أمر آخر : ألا يمكنك القيام بالتحديث عبر الشبكة .. بحيث تنفذ التحديث في نفس الوقت؟

نعم يمكن هناك تطبيقات كثيرة لهذا الغرض. ما يتعبني أكثر هو فك DF وإعادة التشغيل لكل جهاز على حدة ولو أنها ليست بذات قضية كبرى كون العدد بسيط.

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#13
Xacker كتب:
سأفيدك بها غداً لو أردت.

لا تتعب نفسك .. فقط أردت أن أستعلم قبل بداية العملية

مع أنني أظن أن توفير هذه المعلومة مفيدة لنا كلنا (أصحاب النسخ [...]) :D

و جيد أنك تفكر في توفير أحسن خدمة للزبون .. عندما يقطعون الإنترنت علي سآتي عندك .. لكني لا أعمل إلا على السرفر :P

:)

مواضيع مشابهة