Portable Data exFiltration XSS for PDFs Gareth Heyes
>> YOUR LINK HERE: ___ http://youtube.com/watch?v=Sz-zEDNTe8U
Gareth Heyes presents his latest research - Portable Data exFiltration XSS for PDFs. This is the director's cut of the presentation that premiered at Black Hat Europe on December 10th, 2020. Read the full whitepaper: https://portswigger.net/research/port... • PDF documents and PDF generators are ubiquitous on the web, and so are injection vulnerabilities. Did you know that controlling a measly HTTP hyperlink can provide a foothold into the inner workings of a PDF? In this session, you will learn how to use a single link to compromise the contents of a PDF and exfiltrate it to a remote server, just like a blind XSS attack. • Resources: • https://insert-script.blogspot.com/20... • https://speakerdeck.com/ange/lets-wri... • https://docs.google.com/presentation/...
#############################
![](http://youtor.org/essay_main.png)