Explore the security vulnerabilities of PDF documents and generators in this 33-minute Black Hat conference talk. Learn how a simple HTTP hyperlink can be exploited to gain access to a PDF's internal structure. Discover techniques for compromising PDF contents using a single link, and understand the implications for web security. Gain insights into the intersection of injection vulnerabilities and widely-used PDF technologies. Presented by Gareth Heyes, this session offers valuable knowledge for security professionals and web developers concerned with PDF-related risks.
Overview
Syllabus
Portable Data exFiltration: XSS for PDFs
Taught by
Black Hat