News: 1622011571

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Contract killer: Certified PDFs can be secretly tampered with during the signing process, boffins find

(2021/05/26)


A pair of techniques to surreptitiously alter the content of certified PDFs have been detailed by researchers in Germany.

The upshot is that someone could digitally add their signature to a PDF of, say, a contract, pass the file to a partner to digitally sign, and that second person could sneakily alter the contract's text as well as sign it, creating confusion down the line. While the addition of the second signature would be permitted, the tampering of the text should be detected and flagged up by application software – unless the second person uses the aforementioned techniques.

The exploits, dubbed Evil Annotation and Sneaky Signature, are detailed in a paper

[1]PDF

and [2]website by Ruhr University Bochum's Simon Rohlmann, Dr Vladislav Mladenov, Dr Christian Mainka, and Professor Jörg Schwenk. The team were due to present their work at the 42nd IEEE Symposium on Security and Privacy, taking place online this week.

[3]

[4]

[5]

Their discovery would be a boon to scammers, and while the developers of major PDF-generation applications, such as Adobe, Libreoffice, and Foxit, have now patched their code to thwart the techniques, the makers of minor PDF tools have been slower to respond.

Using certified PDFs is increasingly common in business. The creator of such a document can allow some content changes, such as adding a digital signature or side notes, without tripping any alarms. However, the team found that some of these annotation fields can be manipulated to introduce new material and change the meaning of the text.

With the Evil Annotation attack, the boffins found three annotations – FreeText, Redact, and Stamp – could be subverted to allow images or new text to be inserted into a document without the creator being aware. "All three can be used to stealthily modify a certified document and inject malicious content," their paper explained. "In addition, 11 out of 28 annotations are classified as medium since an attacker can hide content within the certified document."

[6]Compsci boffin publishes proof-of-concept code for 54-year-old zero-day in Universal Turing Machine

[7]University duo thought it would be cool to sneak bad code into Linux as an experiment. Of course, it absolutely backfired

[8]FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins

[9]Hallowed Bugtraq infosec list killed then resurrected over the weekend: We heard your feedback, says Accenture

For documents where the annotations that are allowed to be added are more limited, Sneaky Signature comes into play. The second person to sign the document can do so, and then use that process to add additional information. That is to say, rather than abuse annotations, the signing process is exploited.

"If a certified document is opened in a common PDF application, signatures can only be added to free signature fields provided by the certifier. Adding empty signature fields is normally no longer possible within the application," the paper states.

[10]

"However, the specification does not prohibit adding empty signature fields to a certified document. By using frameworks like Apache PDFBox2, empty signature fields can be placed anywhere in the document and filled with arbitrary content."

The researchers tested 26 popular PDF tools, and found 24 of them were vulnerable to either both of the flaws or just one. The only viewers to get a clean bill of health for this issue were PDF Editor 6 Pro and PDFelement Pro.

The techniques described aren't perfect: the alterations can be later discovered when the PDF files are compared, though by that point, whatever fraud was planned may have been successfully pulled off. In the case of someone inserting new payment details into an invoice or contract to siphon off funds, the money may be long gone by that point.

[11]

As a dark bonus, the team also found a security weakness that specifically hit Adobe products. This could be exploited to embed malicious code in documents with no warning to the recipient, thanks to Adobe's JavaScript policies.

"Only certified documents may execute high privileged JavaScript code in Adobe products," they said. "The attack is not limited to calling up a website but can execute any high privileged JavaScript code. The only requirement is that the victim fully trusts the certificate used to certify the PDFdocument."

Adobe fixed this issue in the start of November following responsible disclosure of the flaw. Many of the other tested applications have also been patched, although some vendors haven't responded – you can see the full list [12]here . Make sure you're up to date with your applications, if you can. ®

Get our [13]Tech Resources



[1] https://pdf-insecurity.org/download/pdf-certification/paper.pdf

[2] https://pdf-insecurity.org/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YK4cQk@DsOZt60UB36RwAAAAAFE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YK4cQk@DsOZt60UB36RwAAAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YK4cQk@DsOZt60UB36RwAAAAAFE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/05/11/turing_machine_0day_no_patch_available/

[7] https://www.theregister.com/2021/04/21/minnesota_linux_kernel_flaws_update/

[8] https://www.theregister.com/2021/04/14/fbi_exchange_server_malware_deletion/

[9] https://www.theregister.com/2021/01/18/security_in_brief_bugtraq/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YK4cQk@DsOZt60UB36RwAAAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YK4cQk@DsOZt60UB36RwAAAAAFE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://pdf-insecurity.org/signature/evaluation.html#security-evaluation-certification-attacks-2021

[13] https://whitepapers.theregister.com/

Jonathon Green

Those aren’t bugs they’re features.

Admittedly not features any sane person would want, need, or consider adding to a secure document exchange format, but then PDF was never meant to be that, and nobody who’d spent more than half-a-day or so examining the spec[1] would ever think it was appropriate to use it for that purpose…

[1] And for my sins I’ve spent a lot more time than that with it…

"secure document exchange format"

William Towle

> PDF was never meant to be that, and nobody who’d spent more than half-a-day or so examining the spec[1] would ever think it was appropriate to use it for that purpose…

Unfortunately, people wanting not to send paper documents -perhaps encouraged by the pandemic- want to use it for that.

I recently had "just use X on your phone to sign [this PDF]" where X wasn't part of the stock android image and I didn't have space to install it, and while I could otherwise sign with libreoffice (after creating certificates and persuading it they existed) I found post-conversion artifacts before I could start ... with the argument "this *needs* to be done on paper" carrying little weight until I decided to stop sending attachments that were meant to be proof (and not finished submissions) :/

I went to look at the PDF .....

KittenHuffer

..... but it had been tampered with!

Hubert Cumberdale

The attacks seem a little complicated... by the sound of it, more complicated than [1]those needed to edit a Scottish vaccination certificate (not sure if those were PDFs, as they are [sensibly] rather coy about the details, but I'm not surprised by any of it).

[1] https://www.bbc.co.uk/news/uk-scotland-57208607

Fools rush in -- and get the best seats in the house.