Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Adobe reader plugin PDF files universal crossite scripting

  Adobe Acrobat Reader Plugin - Multiple Vulnerabilities

  [Full-disclosure] Universal XSS with PDF files: highly dangerous

From:Maximize Designs <emeckz_(at)_gmail.com>
Date:03.01.2007
Subject:Re: Unpatchable Quicktime XSS

New MySpace XSS by Mx http://mxcore.com for more info

What you need:
Adobe Acrobat Professional (7.0 works)
A server to host the PDF in

1. Open up Adobe Acrobat Professional.
2. File > Create PDF > I did From File, but you can do whatever you want.
This step explains itself pretty much.
3. You now have a new PDF file. Now what do you do? Simple. Click the
"Pages" tab on the left side.
4. You will now see a thumbnail view of all the pages in your new PDF file
(usually it's just one page).
5. Right click on that thumbnail and select "Page PropertieS"
6. Click on the 'Actions' tab.
**7. For "Select Trigger" choose "Page Open"
**8. For "Select Action" choose "Open a web link".
9. Now click the "Add" button below.
10. Enter the URL you'd like to redirect to in the pop up box.
11. Save the PDF file (Ctrl + S, or File > Save)
12. Host it on any page.
13. Embed using the following code:
<embed src="http://linktoyour.pdf">

Finished!

Congrats! :p


** Marks that the step can be modified to fit your needs by selecting a
different option. In other words, it means you can mess around with that
step.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server