<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: PDF Security &#8211; Avoiding Exploits</title> <atom:link href="http://www.pcmech.com/article/pdf-security-avoiding-exploits/feed/" rel="self" type="application/rss+xml" /><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/</link> <description>Helping Normal People Get Their Geek On</description> <lastBuildDate>Wed, 15 Feb 2012 10:29:00 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Steve RJ</title><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/comment-page-1/#comment-16963</link> <dc:creator>Steve RJ</dc:creator> <pubDate>Mon, 17 Nov 2008 23:28:07 +0000</pubDate> <guid
isPermaLink="false">http://www.pcmech.com/?p=8417#comment-16963</guid> <description>Early versions of Foxit reader did not support javascript.  I know this because our company tested LockLizard viewer for secure PDF files, which we were told was based on the Foxit version 1 SDK, and javascript is not supported.  In fact all active content is prevented from loading, but it only works with LockLizard protected PDF files.  I guess we are back to the age old question of security vs usability...</description> <content:encoded><![CDATA[<p>Early versions of Foxit reader did not support javascript.  I know this because our company tested LockLizard viewer for secure PDF files, which we were told was based on the Foxit version 1 SDK, and javascript is not supported.  In fact all active content is prevented from loading, but it only works with LockLizard protected PDF files.  I guess we are back to the age old question of security vs usability&#8230;</p> ]]></content:encoded> </item> <item><title>By: Joel</title><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/comment-page-1/#comment-16682</link> <dc:creator>Joel</dc:creator> <pubDate>Mon, 10 Nov 2008 21:22:42 +0000</pubDate> <guid
isPermaLink="false">http://www.pcmech.com/?p=8417#comment-16682</guid> <description>Even the exploit doesn&#039;t affect Adobe Reader version 9 is good to disable JavaScript just in case. About FoxReader there must be a way to disable JavaScript also or at least another version that covers this hole.</description> <content:encoded><![CDATA[<p>Even the exploit doesn&#8217;t affect Adobe Reader version 9 is good to disable JavaScript just in case. About FoxReader there must be a way to disable JavaScript also or at least another version that covers this hole.</p> ]]></content:encoded> </item> <item><title>By: John Kirkham</title><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/comment-page-1/#comment-16616</link> <dc:creator>John Kirkham</dc:creator> <pubDate>Sat, 08 Nov 2008 06:44:26 +0000</pubDate> <guid
isPermaLink="false">http://www.pcmech.com/?p=8417#comment-16616</guid> <description>Same as SAP said but I thought this problem was only tested &amp; found in Foxit first up in the last week.</description> <content:encoded><![CDATA[<p>Same as SAP said but I thought this problem was only tested &amp; found in Foxit first up in the last week.</p> ]]></content:encoded> </item> <item><title>By: SAP</title><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/comment-page-1/#comment-16595</link> <dc:creator>SAP</dc:creator> <pubDate>Fri, 07 Nov 2008 14:38:12 +0000</pubDate> <guid
isPermaLink="false">http://www.pcmech.com/?p=8417#comment-16595</guid> <description>I&#039;ve just noticed that the Net Security article cited in the article specifically says that the Adobe Reader bug is the same as the previously discovered bug in FoxIt.Foxit *was* affected by the bug (CVE-2008-1104), but it was fixed some time ago.So presumably Foxit Reader does support Javascript.Though it is much smaller and quicker to load than Adobese Reader.</description> <content:encoded><![CDATA[<p>I&#8217;ve just noticed that the Net Security article cited in the article specifically says that the Adobe Reader bug is the same as the previously discovered bug in FoxIt.</p><p>Foxit *was* affected by the bug (CVE-2008-1104), but it was fixed some time ago.</p><p>So presumably Foxit Reader does support Javascript.</p><p>Though it is much smaller and quicker to load than Adobese Reader.</p> ]]></content:encoded> </item> <item><title>By: SAP</title><link>http://www.pcmech.com/article/pdf-security-avoiding-exploits/comment-page-1/#comment-16594</link> <dc:creator>SAP</dc:creator> <pubDate>Fri, 07 Nov 2008 14:23:22 +0000</pubDate> <guid
isPermaLink="false">http://www.pcmech.com/?p=8417#comment-16594</guid> <description>I have seen a PDF file containing some forms to fill in.There was some scripting involved which checked that the appropriate fields had been completed. Perhaps that is what Javascript is for.One advantage of using JS rather than inventing a new scripting language is that people don&#039;t need to learn a new language.However, JS *should* have been added in such a way that it could only be used to affect elements within the PDF.</description> <content:encoded><![CDATA[<p>I have seen a PDF file containing some forms to fill in.</p><p>There was some scripting involved which checked that the appropriate fields had been completed. Perhaps that is what Javascript is for.</p><p>One advantage of using JS rather than inventing a new scripting language is that people don&#8217;t need to learn a new language.</p><p>However, JS *should* have been added in such a way that it could only be used to affect elements within the PDF.</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using apc
Page Caching using apc
Database Caching 33/46 queries in 0.018 seconds using apc
Content Delivery Network via pcmech.pcmediainc.netdna-cdn.com

Served from: www.pcmech.com @ 2012-02-15 12:48:05 -->
