Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
1–10 of 60 posts
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#2I ... think there’s another technique that relies a bit on trusting the printing drivers to do the right thing, where you can tell Ghostscript to print your document, and target another PDF. This should at least remove interactive components in a PDF
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#3I don't open any files on my PC from people I don't personally know -- use webviewers.
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#4This is definitely a good brute force strategy I ... think there’s another technique that relies a bit on trusting the printing drivers to do the right thing, where you can tell Ghostscript to print your document, and target another PDF. This should at least remove interactive components in a PDF
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#5Useful tool -- it's trivial to make a RAT bypass chat/email .doc/.PDF attachments. I don't open any files on my PC from people I don't personally know -- use webviewers.
edit: Thank you for both answers. I thought it had to do with sandbox rationale, but couldn't mentally get past the fact that sandbox could potentially be escaped too. Eh, I think it is time for sleep.
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#6Useful tool -- it's trivial to make a RAT bypass chat/email .doc/.PDF attachments. I don't open any files on my PC from people I don't personally know -- use webviewers.
Odd question. Why would a webviewer be safer in this case? edit: Thank you for both answers. I thought it had to do with sandbox rationale, but couldn't mentally get past the fact that sandbox could potentially be escaped too. Eh, I think it is time for sleep.
Safer: definitely. Given that the collective amount of PDF attacks is some number, now this particular PDF needs to attack PDF and the webviewer. Assuming that 1% of all PDFs do that, I'd say it's 100 times safer than not using a webviewer.
If you still think that 1% of all potential PDF attacks is too unsafe, then that's a different discussion.
If you think my 1% is off, then that's a different discussion too. All I'm saying is that it's safer.
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#7Useful tool -- it's trivial to make a RAT bypass chat/email .doc/.PDF attachments. I don't open any files on my PC from people I don't personally know -- use webviewers.
Odd question. Why would a webviewer be safer in this case? edit: Thank you for both answers. I thought it had to do with sandbox rationale, but couldn't mentally get past the fact that sandbox could potentially be escaped too. Eh, I think it is time for sleep.
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#8This is definitely a good brute force strategy I ... think there’s another technique that relies a bit on trusting the printing drivers to do the right thing, where you can tell Ghostscript to print your document, and target another PDF. This should at least remove interactive components in a PDF
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#9Earlier quoted context omitted.
Odd question. Why would a webviewer be safer in this case? edit: Thank you for both answers. I thought it had to do with sandbox rationale, but couldn't mentally get past the fact that sandbox could potentially be escaped too. Eh, I think it is time for sleep.
Well is it safe? Don't know. Safer: definitely. Given that the collective amount of PDF attacks is some number, now this particular PDF needs to attack PDF and the webviewer. Assuming that 1% of all PDFs do that, I'd say it's 100 times safer than not using a webviewer. If you still think that 1% of all potential PDF attacks is too unsafe, then that's a different discussion. If you think my 1% is off, then that's a di…
Re: Dangerzone: Convert potentially dangerous PDFs, documents, or images to safe PDF
#10This is definitely a good brute force strategy I ... think there’s another technique that relies a bit on trusting the printing drivers to do the right thing, where you can tell Ghostscript to print your document, and target another PDF. This should at least remove interactive components in a PDF
I used to deal with PDF at my day job. Among all the tools we use in production, Ghostscript probably has the most 0 day. Thankfully we're paranoid about security and run everything in sandbox. Still it's no fun getting nagged by security to upgrade our Ghostscript version.
https://bugs.chromium.org/p/project-zero/issues/detail?id=16...