Exploring the Blackhole exploit kit

A technical paper by Fraser Howard, SophosLabs, UK

Table of contents

← Prev | Next →

6.3 Appendix 3: PDF ‘type 2’

The deobfuscated and prettified JavaScript from ‘type 1’ PDFs used by Blackhole. The base64-encoded body of a TIFF file is created by the JavaScript, in order to exploit CVE-2010-0188.

Appendix 2a

Appendix 2b

Table of contents

← Prev | Next →

What do you think?