<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on World&#39;s Smallest PDF</title>
	<subtitle>Acrobat will parse some very badly formed PDF files. It&#39;s possible to remove almost everything from a PDF file, and still launch Javascript. A minimum of 58 bytes are all that is required to execute Javascript within Acrobat.</subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on World&#39;s Smallest PDF" href="http://blog.fireeye.com/research/2010/06/that-pdf-thing/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="World&#39;s Smallest PDF" href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2010-06-15T21:35:25Z</updated>
	<author>
		<name>FireEye, Inc.</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2010/06/that-pdf-thing/comments/atom.xml/</id>
    
		<entry>
			<title>Julia Wolf commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="&gt; Do you want to make a post / analysis about this http://seclists.org/fulldisclosure/2010/Jul/7 case? I suppose I could, though it&#39;s..." href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef0134852789df970c#comment-6a00d835018afd53ef0134852789df970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0134852789df970c</id>
			<published>2010-07-02T09:33:44Z</published>
			<updated>2010-07-02T09:33:44Z</updated>
			<author>
				<name>Julia Wolf</name>
                <uri>http://blog.fireeye.com/</uri>
			</author>
			<summary>&gt; Do you want to make a post / analysis about this http://seclists.org/fulldisclosure/2010/Jul/7 case? I suppose I could, though it&#39;s...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;&amp;gt; Do you want to make a post / analysis about this &lt;a href=&quot;http://seclists.org/fulldisclosure/2010/Jul/7&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/fulldisclosure/2010/Jul/7&lt;/a&gt;  case?&lt;/p&gt;

&lt;p&gt;I suppose I could, though it&amp;#39;s not terribly new or interesting. There is a ton of this sort of activity every day, and has been for years. This particular spam campaign was also pretending to be from wordpress.com, also saying that you&amp;#39;d just signed up for an account, with all links leading to that infectious PDF. (Which used one of three possible exploits, all at least a year old.) &lt;/p&gt;

&lt;p&gt;Using the message attached to that FD post, this particular article of spam was send from 202.13.62.5. Observe:&lt;br /&gt;
[...]&lt;br /&gt;
&amp;gt; Received: from TUHWJATY (unknown [202.133.62.5])&lt;br /&gt;
&amp;gt;         by stg.iki.fi (Postfix) with ESMTP id 26EC819D5C&lt;br /&gt;
&amp;gt;         for ; Thu,  1 Jul 2010 13:25:28 +0300 (EEST)&lt;br /&gt;
&amp;gt; Received: from 202.133.62.5 (port=0267 helo=[swaraj])&lt;br /&gt;
&amp;gt;         by mail.ragoarts.com with asmtp &lt;br /&gt;
&amp;gt;         id 981EFE-000841-91&lt;br /&gt;
&amp;gt;         for ______hack.fi; Thu, 1 Jul 2010 15:56:02 +0530&lt;/p&gt;

&lt;p&gt;&amp;gt; Someone from the IP address 202.133.62.5 has registered the account &amp;quot;fgeek&amp;quot; with [...]&lt;/p&gt;

&lt;p&gt;  The IP address of the spam drone is included in the body text, as well as the recipient username. Every single message is like this, just with the corresponding values filled in.&lt;/p&gt;

&lt;p&gt;  If it wasn&amp;#39;t 2:30am, and I didn&amp;#39;t have something else to be finishing right now, I&amp;#39;d probably lookup the name of whichever particular spam bot this is.&lt;/p&gt;

&lt;p&gt;(I&amp;#39;ve redacted the email address of the recipient, just to avoid that much more spam sent to them.)&lt;/p&gt;

&lt;p&gt;I think you&amp;#39;ll find this illuminating:&lt;br /&gt;
&lt;a href=&quot;http://www.google.com/search?q=http%3A%2F%2Fchipsnchils.com%2Fwordpress.html&quot; rel=&quot;nofollow&quot;&gt;http://www.google.com/search?q=http%3A%2F%2Fchipsnchils.com%2Fwordpress.html&lt;/a&gt;&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Henri Salo commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="Do you want to make a post / analysis about this http://seclists.org/fulldisclosure/2010/Jul/7 case?" href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef0133f1fe467e970b#comment-6a00d835018afd53ef0133f1fe467e970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0133f1fe467e970b</id>
			<published>2010-07-01T17:19:54Z</published>
			<updated>2010-07-01T17:19:54Z</updated>
			<author>
				<name>Henri Salo</name>
                
			</author>
			<summary>Do you want to make a post / analysis about this http://seclists.org/fulldisclosure/2010/Jul/7 case?</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;Do you want to make a post / analysis about this &lt;a href=&quot;http://seclists.org/fulldisclosure/2010/Jul/7&quot; rel=&quot;nofollow&quot;&gt;http://seclists.org/fulldisclosure/2010/Jul/7&lt;/a&gt; case?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Comment commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="ePDFViewer on Ubuntu show &quot;encrypted document. Enter password&quot; popup." href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef013484e44102970c#comment-6a00d835018afd53ef013484e44102970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef013484e44102970c</id>
			<published>2010-06-24T22:17:09Z</published>
			<updated>2010-06-24T22:17:09Z</updated>
			<author>
				<name>Comment</name>
                
			</author>
			<summary>ePDFViewer on Ubuntu show &quot;encrypted document. Enter password&quot; popup.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;ePDFViewer on Ubuntu show &amp;quot;encrypted document. Enter password&amp;quot; popup.&lt;/p&gt;

&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Julia Wolf commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="Yeah, I expect that *everything* except for Adobe Acrobat 9.1.3 is going to error out. This PDF file is way-way-way..." href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef0133f18e1101970b#comment-6a00d835018afd53ef0133f18e1101970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0133f18e1101970b</id>
			<published>2010-06-22T01:15:25Z</published>
			<updated>2010-06-22T01:15:25Z</updated>
			<author>
				<name>Julia Wolf</name>
                <uri>http://blog.fireeye.com/</uri>
			</author>
			<summary>Yeah, I expect that *everything* except for Adobe Acrobat 9.1.3 is going to error out. This PDF file is way-way-way...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;Yeah, I expect that *everything* except for Adobe Acrobat 9.1.3 is going to error out. This PDF file is way-way-way out of spec. Older versions of Acrobat won&amp;#39;t even read this.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>joe blow commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="Same for okular on gentoo. Error: PDF file is damaged - attempting to reconstruct xref table... Error: Couldn&#39;t find trailer..." href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef0133f18ddfe1970b#comment-6a00d835018afd53ef0133f18ddfe1970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0133f18ddfe1970b</id>
			<published>2010-06-22T00:50:04Z</published>
			<updated>2010-06-22T00:50:04Z</updated>
			<author>
				<name>joe blow</name>
                
			</author>
			<summary>Same for okular on gentoo. Error: PDF file is damaged - attempting to reconstruct xref table... Error: Couldn&#39;t find trailer...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;Same for okular on gentoo.&lt;/p&gt;

&lt;p&gt;Error: PDF file is damaged - attempting to reconstruct xref table...&lt;br /&gt;
Error: Couldn&amp;#39;t find trailer dictionary&lt;br /&gt;
Error: Couldn&amp;#39;t read xref table&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Robin commented on &#39;World&#39;s Smallest PDF&#39;</title>
			<link rel="alternate" type="text/html" title="evince in Debian fails to read the 71 byte version: Error: PDF file is damaged - attempting to reconstruct xref..." href="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html?cid=6a00d835018afd53ef0133f18b397f970b#comment-6a00d835018afd53ef0133f18b397f970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0133f18b397f970b</id>
			<published>2010-06-21T21:20:31Z</published>
			<updated>2010-06-21T21:20:31Z</updated>
			<author>
				<name>Robin</name>
                <uri>http://www.digininja.org</uri>
			</author>
			<summary>evince in Debian fails to read the 71 byte version: Error: PDF file is damaged - attempting to reconstruct xref...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2010/06/that-pdf-thing.html">&lt;p&gt;evince in Debian fails to read the 71 byte version:&lt;/p&gt;

&lt;p&gt;Error: PDF file is damaged - attempting to reconstruct xref table...&lt;br /&gt;
Error: Couldn&amp;#39;t find trailer dictionary&lt;br /&gt;
Error: Couldn&amp;#39;t read xref table&lt;br /&gt;
Error: PDF file is damaged - attempting to reconstruct xref table...&lt;br /&gt;
Error: Couldn&amp;#39;t find trailer dictionary&lt;br /&gt;
Error: Couldn&amp;#39;t read xref table&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
</feed>

<!-- ph=1 -->