<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>System7 &#187; javascript</title>
	<atom:link href="http://www.system7.org/tag/javascript/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.system7.org</link>
	<description>Spread the word, information is free.</description>
	<lastBuildDate>Mon, 16 Jan 2012 13:24:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Analyzing Malicious PDF Documents</title>
		<link>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/</link>
		<comments>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 11:50:00 +0000</pubDate>
		<dc:creator>.</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[re]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.system7.org/?p=513</guid>
		<description><![CDATA[So you want to get your feet wet? Grab Didier Stevens tools here: http://blog.didierstevens.com/programs/pdf-tools/ Grab malicious PDF samples here: http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&#38;colsearch=All&#38;quantity=50 *Be careful, these are live samples! Video Tutorial: Didier on analyzing a PDF Document: http://www.youtube.com/v/tHVi2wKCkTc You&#8217;re going to run into &#8230; <a href="http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>So you want to get your feet wet?</p>
<ol>
<li>Grab Didier Stevens tools here: <a href="http://blog.didierstevens.com/programs/pdf-tools/">http://blog.didierstevens.com/programs/pdf-tools/</a></li>
<li>Grab malicious PDF samples here: <a href="http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50">http://www.malwaredomainlist.com/mdl.php?search=pdf+exploit&amp;colsearch=All&amp;quantity=50</a> *Be careful, these are live samples!</li>
<li>Video Tutorial: Didier on analyzing a PDF Document: <a title="YouTube: Analyzing a malicious PDF document" href="http://www.youtube.com/v/tHVi2wKCkTc">http://www.youtube.com/v/tHVi2wKCkTc</a></li>
<li>You&#8217;re going to run into some heavily obfuscated JavaScript.  Read this article: <a href="http://isc.sans.org/diary.html?storyid=2358">http://isc.sans.org/diary.html?storyid=2358</a></li>
<li>Other deobfuscation tools: <a href="http://malzilla.sourceforge.net/">Malzilla</a>, <a href="http://www.mozilla.org/js/spidermonkey/">SpiderMonkey</a> (need to handle document.write), debug via <a href="http://www.mozilla.org/rhino/">Rhino</a>, <a href="https://addons.mozilla.org/en-US/firefox/addon/10345">Firefox add-on</a> (haven&#8217;t tried this one)</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.system7.org/2010/04/20/analyzing-malicious-pdf-documents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

