Monday, July 11, 2011

PDF Structure

I have spent 15 years working with PDF structure.  I am impressed with how little various "hackers" and "security" people really know about its internal format - how little the tools really do.

Most tools simply dump out superficial dumps of streams and other content structures.

The real vulnerability of PDF is the CosObj structure and how its processed.  Most constructs are poorly defined in the "standard" and therefore subject to "issues".  Acrobat has been a source of consistent issues for me for the last decade and a half or so...

No comments:

Post a Comment