Studying, Finding, and Localizing Inconsistency Bugs in PDF Readers and Files
Total Page:16
File Type:pdf, Size:1020Kb
Load more
Recommended publications
-
Vulnerability Report Attacks Bypassing Confidentiality in Encrypted PDF
Vulnerability Report Attacks bypassing confidentiality in encrypted PDF Jens M¨uller1, Fabian Ising2, Vladislav Mladenov1, Christian Mainka1, Sebastian Schinzel2, J¨orgSchwenk1 May 16, 2019 1Chair for Network and Data Security 2FH M¨unsterUniversity of Applied Sciences Abstract In this report, we analyze PDF encryption and show two novel techniques for breaking the confidentiality of encrypted documents. Firstly, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within attacker-controlled content and therefore, exfiltrate the plaintext once the document is opened by a legitimate user. Secondly, we abuse a flaw in the PDF encryption specification allowing an attacker to arbitrarily manipulate encrypted content without knowing the cor- responding key/password. The only requirement is one single block of known plaintext, which we show is fulfilled by design. By using exfiltration channels our attacks allow the recovery of the entire plaintext or parts of it within an encrypted document. The attacks rely only on standard compliant PDF features. We evaluated our attacks on 27 widely used PDF viewers and found all of them vulnerable. 1 Contents 1 Background4 1.1 Portable Document Format (PDF) . .4 1.2 PDF Encryption . .6 1.3 PDF Interactive Features . .7 2 Attacker Model8 3 PDF Encryption: Security Analysis9 3.1 Partial Encryption . .9 3.2 CBC Malleability . 10 3.3 PDF Interactive Features . 12 4 How To Break PDF Encryption 14 4.1 Direct Exfiltration (Attack A) . 14 4.1.1 Requirements . 15 4.1.2 Direct Exfiltration through PDF Forms (A1) . 15 4.1.3 Direct Exfiltration via Hyperlinks (A2) . -
4Typesetting, Viewing and Printing
Typesetting, viewing 4and printing We’ve now got far enough to typeset what you’ve entered. I’m assuming at this stage that you have typed some sample text in the format specified in the previous chapter, and you’ve saved it in a plain•text file with a filetype of .tex and a name of your own choosing. Picking suitable filenames Never, ever use directories (folders) or file names which contain spaces. Although your op• erating system probably supports them, some don’t, and they will only cause grief and tears with TEX. Make filenames as short or as long as you wish, but strictly avoid spaces. Stick to upper• and lower•case letters without accents (A–Z and a–z), the digits 0–9, the hyphen (-), and the full point or period (.), (similar to the conventions for a Web URI): it will let you refer to TEX files over the Web more easily and make your files more portable. Formatting information ✄ 63 ✂ ✁ CHAPTER 4. TYPESETTING, VIEWING AND PRINTING Exercise 4.1: Saving your file If you haven’t already saved your file, do so now (some editors and interfaces let you type• set the document without saving it!). Pick a sensible filename in a sensible directory. Names should be short enough to display and search for, but descriptive enough to make sense. See the panel ‘Picking suitable file• names’ above for more details. 4.1 Typesetting Typesetting your document is usually done by clicking on a button in a toolbar or an entry in a menu. Which one you click on depends on what output you want — there are two formats available: A f The standard (default) LTEX program produces a device•independent (DVI) file which can be used with any TEX previewer or printer driver on any make or model of computer. -
How Is Video Game Development Different from Software Development in Open Source?
Delft University of Technology How Is Video Game Development Different from Software Development in Open Source? Pascarella, Luca; Palomba, Fabio; Di Penta, Massimiliano; Bacchelli, Alberto DOI 10.1145/3196398.3196418 Publication date 2018 Document Version Accepted author manuscript Published in Proceedings of the 15th International Conference on Mining Software Repositories, MSR. ACM, New York, NY Citation (APA) Pascarella, L., Palomba, F., Di Penta, M., & Bacchelli, A. (2018). How Is Video Game Development Different from Software Development in Open Source? In Proceedings of the 15th International Conference on Mining Software Repositories, MSR. ACM, New York, NY (pp. 392-402) https://doi.org/10.1145/3196398.3196418 Important note To cite this publication, please use the final published version (if applicable). Please check the document version above. Copyright Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons. Takedown policy Please contact us and provide details if you believe this document breaches copyrights. We will remove access to the work immediately and investigate your claim. This work is downloaded from Delft University of Technology. For technical reasons the number of authors shown on this cover page is limited to a maximum of 10. How Is Video Game Development Different from Software Development in Open Source? Luca Pascarella1, -
Living Without Google on Android
Alternative for Google Apps on Android - living without Google on Android Android without any Google App? What to use instead of Hangouts, Map, Gmail? Is that even possible? And why would anyone want to live without Google? I've been using a lot of different custom ROMs on my devices, so far the two best: plain Cyanogenmod 11 snapshot on the Nexus 4[^1], and MIUI 2.3.2 on the HTC Desire G7[^2]. All the others ( MUIU 5, MIUI 6 unofficial, AOKP, Kaos, Slim, etc ) were either ugly, unusable, too strange or exceptionally problematic on battery life. For a long time, the first step for me was to install the Google Apps, gapps packages for Plays Store, Maps, and so on, but lately they require so much rights on the phone that I started to have a bad taste about them. Then I started to look for alternatives. 1 of 5 So, what to replace with what? Play Store I've been using F-Droid[^3] as my primary app store for a while now, but since it's strictly Free Software[^4] store only, sometimes there's just no app present for your needs; aptoide[^5] comes very handy in that cases. Hangouts I never liked Hangouts since the move from Gtalk although for a little while it was exceptional for video - I guess it ended when the mass started to use it in replacement of Skype and its recent suckyness. For chat only, check out: ChatSecure[^6], Conversations[^7] or Xabber[^8]. All of them is good for Gtalk-like, oldschool client and though Facebook can be configured as XMPP as well, I'd recommend Xabber for that, the other two is a bit flaky with Facebook. -
Ghostscript and Mupdf Status Openprinting Summit April 2016
Ghostscript and MuPDF Status OpenPrinting Summit April 2016 Michael Vrhel, Ph.D. Artifex Software Inc. San Rafael CA Outline Ghostscript overview What is new with Ghostscript MuPDF overview What is new with MuPDF MuPDF vs Ghostscript MuJS, GSView The Basics Ghostscript is a document conversion and rendering engine. Written in C ANSI 1989 standard (ANS X3.159-1989) Essential component of the Linux printing pipeline. Dual AGPL/Proprietary licensed. Artifex owns the copyright. Source and documentation available at www.ghostscript.com Graphical Overview PostScript PCL5e/c with PDF 1.7 XPS Level 3 GL/2 and RTL PCLXL Ghostscript Graphics Library High level Printer drivers: Raster output API: Output drivers: Inkjet TIFF PSwrite PDFwrite Laser JPEG XPSwrite Custom etc. CUPS Devices Understanding devices is a major key to understanding Ghostscript. Devices can have high-level functionality. e.g. pdfwrite can handle text, images, patterns, shading, fills, strokes and transparency directly. Graphics library has “default” operations. e.g. text turns into bitmaps, images decomposed into rectangles. In embedded environments, calls into hardware can be made. Raster devices require the graphics library to do all the rendering. Relevant Changes to GS since last meeting…. A substantial revision of the build system and GhostPDL directory structure (9.18) GhostPCL and GhostXPS "products" are now built by the Ghostscript build system "proper" rather than having their own builds (9.18) New method of internally inserting devices into the device chain developed. Allows easier implementation of “filter” devices (9.18) Implementation of "-dFirstPage"/"-dLastPage" with all input languages (9.18) Relevant Changes to GS since last meeting…. -
Breaking PDF Encryption
Practical Decryption exFiltration: Breaking PDF Encryption Jens Müller Fabian Ising Vladislav Mladenov [email protected] [email protected] [email protected] Ruhr University Bochum, Chair for Münster University of Applied Ruhr University Bochum, Chair for Network and Data Security Sciences Network and Data Security Christian Mainka Sebastian Schinzel Jörg Schwenk [email protected] [email protected] [email protected] Ruhr University Bochum, Chair for Münster University of Applied Ruhr University Bochum, Chair for Network and Data Security Sciences Network and Data Security ABSTRACT Home/Trusted Environment The Portable Document Format, better known as PDF, is one of the Decrypted Document 1. Victim opens 2. Exfiltrating Tax Declaration decrypted content most widely used document formats worldwide, and in order to en- an encrypted PDF file Scrooge McDuck with their password via the Internet sure information confidentiality, this file format supports document TOP SECRET Victim encryption. In this paper, we analyze PDF encryption and show Attacker two novel techniques for breaking the confidentiality of encrypted Victim’s PC documents. First, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within Figure 1: An overview of the attack scenario: The victim attacker-controlled content and therefore, exfiltrate the plaintext opens an encrypted PDF document and unintentionally once the document is opened by a legitimate user. Second, we abuse leaks the decrypted content to an attacker-controlled server. a flaw in the PDF encryption specification to arbitrarily manipulate The encrypted PDF file was manipulated by the attacker be- encrypted content. -
The Journal of AUUG Inc. Volume 21 ¯ Number 1 March 2000
The Journal of AUUG Inc. Volume 21 ¯ Number 1 March 2000 Features: Linux under Sail 8 Aegis and Distributed Development 18 News: It’s Election,Time 11 Sponsorship Opportunities AUUG2K 33 Regulars: Meet the Exec 29 My Home Network 31 Book Reviews 36 The Open Source Lucky Dip 39 Unix Traps and Tricks 45 ISSN 1035-7521 Print post approved by Australia Post - PP2391500002 AUUG Membership and General Correspondence Editorial The AUUG Secretary G~nther Feuereisen PO Box 366 [email protected] Kensington NSW 2033 Telephone: 02 8824 9511 or 1800 625 655 (Toll-Free) Facsimile: 02 8824 9522 Welcome to Y2K. I hope all of you who were involved in the general Emaih [email protected] paranoia that gripped the world, got through unscathed. I spent my New Year watching things tick over - and for the first time at New AUUG Management Committee Year’s, I was glad to NOT see fireworks :-) Emaih [email protected] President: With the start of the year, we start to look to the Elections for the David Purdue AUUG Management Committee. [email protected] Tattersall’s 787 Dandenong Road The AUUG Management Committee (or AUUG Exec) is responsible for East Malvern VIC 3145 looking after your member interests. How AUUG serves you is Its’ primary function. This includes such things as organising the Winter Vice-President: Conference, Symposia around the country, coordinating efforts with Mark White Mark,[email protected] the Chapters, making sure we have enough money to do all these Red Hat Asia-Pacific things, and importantly, making sure that we give you, our Members, Suite 141/45 Cribb Street the best possible value for your Membership dollar. -
Free As in Freedom
Daily Diet Free as in freedom ... • The freedom to run the program, for any purpose (freedom 0). Application Seen elsewhere Free Software Choices • The freedom to study how the program works, and adapt it to Text editor Wordpad Kate / Gedit/Vi/ Emacs your needs (freedom 1). Access to the source code is a precondition for this. Office Suite Microsoft Office KOffice / Open Office • The freedom to redistribute copies so you can help your Word Processor Microsoft Word Kword / Writer Presentation PowerPoint KPresenter / Impress neighbor (freedom 2). Spreadsheet Excel Kexl / Calc • The freedom to improve the program, and release your Mail & Info Manager Outlook Thunderbird / Evolution improvements to the public, so that the whole community benefits (freedom 3). Access to the source code is a Browser Safari, IE Konqueror / Firefox precondition for this. Chat client MSN, Yahoo, Gtalk, Kopete / Gaim IRC mIRC Xchat Non-Kernel parts = GNU (GNU is Not Unix) [gnu.org] Netmeeting Ekiga Kernel = Linux [kernel.org] PDF reader Acrobat Reader Kpdf / Xpdf/ Evince GNU Operating Syetem = GNU/Linux or GNU+Linux CD - burning Nero K3b / Gnome Toaster Distro – A flavor [distribution] of GNU/Linux os Music, video Winamp, Media XMMS, mplayer, xine, player rythmbox, totem Binaries ± Executable Terminal>shell>command line – interface to type in command Partition tool Partition Magic Gparted root – the superuser, administrator Graphics and Design Photoshop, GIMP, Image Magick & Corel Draw Karbon14,Skencil,MultiGIF The File system Animation Flash Splash Flash, f4l, Blender Complete list- linuxrsp.ru/win-lin-soft/table-eng.html, linuxeq.com/ Set up Broadband Ubuntu – set up- in terminal sudo pppoeconf. -
Pymupdf 1.12.2 Documentation » Next | Index Pymupdf Documentation
PyMuPDF 1.12.2 documentation » next | index PyMuPDF Documentation Introduction Note on the Name fitz License Covered Version Installation Option 1: Install from Sources Step 1: Download PyMuPDF Step 2: Download and Generate MuPDF Step 3: Build / Setup PyMuPDF Option 2: Install from Binaries Step 1: Download Binary Step 2: Install PyMuPDF MD5 Checksums Targeting Parallel Python Installations Using UPX Tutorial Importing the Bindings Opening a Document Some Document Methods and Attributes Accessing Meta Data Working with Outlines Working with Pages Inspecting the Links of a Page Rendering a Page Saving the Page Image in a File Displaying the Image in Dialog Managers Extracting Text Searching Text PDF Maintenance Modifying, Creating, Re-arranging and Deleting Pages Joining and Splitting PDF Documents Saving Closing Example: Dynamically Cleaning up Corrupt PDF Documents Further Reading Classes Annot Example Colorspace Document Remarks on select() select() Examples setMetadata() Example setToC() Example insertPDF() Examples Other Examples Identity IRect Remark IRect Algebra Examples Link linkDest Matrix Remarks 1 Remarks 2 Matrix Algebra Examples Shifting Flipping Shearing Rotating Outline Page Description of getLinks() Entries Notes on Supporting Links Homologous Methods of Document and Page Pixmap Supported Input Image Types Details on Saving Images with writeImage() Pixmap Example Code Snippets Point Remark Point Algebra Examples Shape Usage Examples Common Parameters Rect Remark Rect Algebra Examples Operator Algebra for Geometry Objects -
Rstudio and .Rnw-Files
Rstudio and .Rnw-files. The compilation of .Rnw-files requires that both LATEX and R are installed on the computer,1 and furthermore, the R-package knitr must be installed in order for the compilation to work. The example file Rnw_Example.Rnw (that you hopefully got a copy of together with this file), will in addition require that the R-package xtable is installed. There are several editors available for R and LATEX,2 but few of these can deal properly with .Rnw-files. Among editors that can deal with the .Rnw-files, the optimal editor is Emacs, http://www.gnu.org/software/emacs/ (with the packages Auctex, http://www.gnu.org/software/auctex/ and Emacs Speaks Statistics, http:// /ess.r-project.org), but this editor requires some time to get used to (the time invested in learning emacs will pay of quickly, so it’s worthwhile to learn how to use it). For newbies it might be easier to try Rstudio, http://www.rstudio.com, which have a very simple solution for dealing with .Rnw-files, i.e. it’s “push a button”. But it’s important to be aware of some adjustments that must be made in the default settings before attempting to compile any .Rnw-file. Please consult the following support-page (and the links found there) https://support.rstudio.com/hc/ en-us/articles/200552056-Using-Sweave-and-knitr, in order to get up-to-date information about the present defaults in Rstudio, since things might have changed after this document was written in January 2016. -
Referência Debian I
Referência Debian i Referência Debian Osamu Aoki Referência Debian ii Copyright © 2013-2021 Osamu Aoki Esta Referência Debian (versão 2.85) (2021-09-17 09:11:56 UTC) pretende fornecer uma visão geral do sistema Debian como um guia do utilizador pós-instalação. Cobre muitos aspetos da administração do sistema através de exemplos shell-command para não programadores. Referência Debian iii COLLABORATORS TITLE : Referência Debian ACTION NAME DATE SIGNATURE WRITTEN BY Osamu Aoki 17 de setembro de 2021 REVISION HISTORY NUMBER DATE DESCRIPTION NAME Referência Debian iv Conteúdo 1 Manuais de GNU/Linux 1 1.1 Básico da consola ................................................... 1 1.1.1 A linha de comandos da shell ........................................ 1 1.1.2 The shell prompt under GUI ......................................... 2 1.1.3 A conta root .................................................. 2 1.1.4 A linha de comandos shell do root ...................................... 3 1.1.5 GUI de ferramentas de administração do sistema .............................. 3 1.1.6 Consolas virtuais ............................................... 3 1.1.7 Como abandonar a linha de comandos .................................... 3 1.1.8 Como desligar o sistema ........................................... 4 1.1.9 Recuperar uma consola sã .......................................... 4 1.1.10 Sugestões de pacotes adicionais para o novato ................................ 4 1.1.11 Uma conta de utilizador extra ........................................ 5 1.1.12 Configuração -
Er Is Geen Gebrek Aan Linux Applicaties Om Je Foto's Te Bekijken
Afbeelding 1: Foto’s bekijken. (zie afbeelding 1). Gebruik die om naar een directory met foto’s te navigeren. Geeqie gaat meteen op zoek naar foto’s. Bestanden die Geeqie niet als foto herkent, slaat hij gewoon over. Geeqie toont in het centrale deel de eerste foto. Onder de file browser staat de lijst met alle overige gevonden foto’s. Standaard is die lijst alfabetisch gerangschikt. Om bijvoorbeeld op datum te sorteren, klik je beneden op Sort by name. Vervolgens kies je Sort by date. Als je graag een thumb- nail bij de bestandsnaam ziet voor een eerste indruk van de foto, ga je naar View -> Files and Folders. Vink daar Show Thumbnails aan. Door op een bestand in de lijst te klikken, open je de desbetreffende foto. Om achter elkaar door de lijst te lopen zijn de PageUp en PageDown toet- sen handig. Heen en weer scrollen met het muiswieltje heeft hetzelfde effect. Als je dat doet met de Ctrl- toets ingedrukt, zoom je in en uit. Soms maak je meerdere foto’s achter elkaar, bijvoorbeeld met verschillende sluitertijden, om later de foto met de mooiste belichting te kiezen. Het is dan handig om de fo- to’s bij elkaar te zien. Dat doe je via View -> Split. Hier kies je of je twee foto’s naast of juist onder elkaar wilt zien. Met de optie Quad toont Geeqie zelfs vier foto’s tegelijk. Om de foto’s samen in- of uit te zoomen, gebruik je Shift samen met de plus- en mintoetsen van het numerieke deel van je toetsenbord.