Web Hack List

Collected research

Attack - PDF Silent HTTP Form Repurposing Attacks

A malicious PDF form built on Adobe's XFA model puts a javascript: URL in an HTTP submit button's target, so clicking it runs script in the domain hosting the PDF rather than making a cross-domain call. Because Acro JS has no DOM, the browser JavaScript handler is used instead to read document.domain and cookies. Tested positive in Chrome, Firefox, Safari and Opera.

Record

Researcher
Aditya K Sood
Published by
secniche.org
Format
Whitepaper
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aditya K Sood, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .