|
|
|
|
|
by fivesigma
3400 days ago
|
|
Is this length extending [1] the already existing Google attack? [1] https://en.wikipedia.org/wiki/Length_extension_attack Edit: yes, looks like it is. As sp332 and JoachimSchipper mentioned, the novelty here is that it contains specially crafted code in order to conditionally display either picture based on previous data (the diff). I can't grok PDF so I still can't find the condition though. Can PDFs reference byte offsets? This is really clever. Edit #2: I misunderstood the original Google attack. This is just an extension of it. |
|
Edit to your edit: This is more of a JPEG hack than a PDF hack. https://news.ycombinator.com/item?id=13715761