GeistHaus
log in · sign up

GitHub - osnr/horrifying-pdf-experiments: :syringe: Stuff which works in Chrome and maybe Acrobat and Foxit.

github.com

:syringe: Stuff which works in Chrome and maybe Acrobat and Foxit. - osnr/horrifying-pdf-experiments

2 pages link to this URL
The Cursed Computer Iceberg Meme

this is not a hall of shame. the intent is to awaken you to many of the peculiarities and weirdness of computers. hopefully, after reading these articles, you will have learned a lot and will embrace chaos.

2 inbound links website en
JavaScript-based PDF Viewers, Cross Site Scripting, and PDF files

❗️Disclosure: I worked at Smallpdf from January to November 2021. In that period, Smallpdf used PDFTron WebViewer SDK (now Apryse PDF WebViewer) to render PDF files in the browser. This information was public. Interview and first XSS in PDFTron WebViewer In October 2020, I started my job interview with Smallpdf for a Cloud Security Engineer position. During the interview process, I began to use Smallpdf as a service to “play” with it, and being a web application that renders PDF files, I tried to exploit PDF files to inject arbitrary Javascript code.

0 inbound links article en blog