Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Foxit PDF Reader Stored XSS

$
0
0
A friend of mine was performing an external pentest recently and he started to complain that his traditional Java exploits were not being effective. He was able to map a few applications and defenses in place protecting the client's network but he still needed an initial access to start pivoting.

Basic protections like AV, application white-listing as well as more advanced  ones like EMET are used to make the life of criminals (and pentesters) harder, but they're often bypassed. While discussing alternatives with my friend, he told me that the company replaced Adobe Reader after seeing lots of Security Advisories for the product. And what was the replacement? Foxit Reader

more here...........http://w00tsec.blogspot.com/2014/07/foxit-pdf-reader-stored-xss.html

Viewing all articles
Browse latest Browse all 8064

Trending Articles