Death To Acrobat Reader

Acrobat Reader is a constant sore spot for me. Thanks to the various security holes it has in older versions, I’ve had to clean up many a system that have been infected by hidden embedded PDFs that take advantage of those security problems. When I’m cleaning up a system, one of the most common things I’ll do it just flat-out turn off JavaScript in Acrobat or install another PDF reader. Just to be safe, I’ll still turn off JavaScript in FoxIt. Has anybody seen useful JavaScript in PDF files? I haven’t.

Ideally, PDF would be a browser-native format that wouldn’t require plugins or external programs to view them. But there are at least a few other ways to do things: Thanks to Waxy, I now know how I’m going to embed PDFs into pages: Use an undocumnted featured in Google Docs to stick it right on the page. That way hopefully nobody will have Acrobat Reader execute to view the file, which will cause much less trouble for everybody involved.

Apparently other services offer similar functionality, like PDFMeNot.

Sadly, though, if you try to print the embedded document, it still appears to open your default PDF reader, but it’s a step in the right direction.

Comments

Neil T. says:

This is one reason why I like Macs – our preview app also supports PDFs, out of the box.
Unfortunately I mostly use PDF files at work so I’m stuck with Adobe.

Josh says:

This is another solution –
it dynamically intercepts PDF’s and uploads them onto their server for viewing.
https://addons.mozilla.org/en-US/firefox/addon/10965

New York Times Serves Up Malware

Some folks who visited the NYT’s web site over the weekend were greeted with a warning that their system was infected with all sorts of crap. Their ad system had…