Don’t take LTEX files from strangers

نویسندگان

  • Steve Checkoway
  • Hovav Shacham
  • Eric Rescorla
چکیده

TEX, LTEX, and BibTEX files are a common method of collaboration for computer science professionals. It is widely assumed by users that LTEX files are safe; that is, that no significant harm can come of running LTEX on an arbitrary computer. Unfortunately, this is not the case: In this article we describe how to exploit LTEX to build a virus that spreads between documents on the MiKTEX distribution on Windows XP as well as how to use malicious documents to steal data from web-based LTEX previewer services.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Don’t take LaTeX files from strangers

[email protected] TEX , L ATEX , AND B I B T EX F I L ES ARE a common method of collaboration for computer science professionals. It is widely assumed by users that LaTeX files are safe; that is, that no significant harm can come of running LaTeX on an arbitrary computer. Unfortunately, this is not the case. In this article we describe how to exploit LaTeX to build a virus that spreads between docum...

متن کامل

TEX Tour , part 1 : The basic distribution

Introduction In this article I hope to give a ‘guided tour’ around the files that make up the basic LTEX distribution. Subsequent articles in this mini-series will cover other packages by the LTEX development team, and also some of the main contributed packages. The primary source for LTEX is the ‘CTAN ’ network of archives, so if I refer to path names of files this relates to the CTAN file str...

متن کامل

User-friendly Web Utilities for Generating L a T E X Output and Metapost Graphics

There are several facets of the creation of LTEX documents and METAPOST graphics that deter users from initially trying both LTEX and METAPOST. These include the basic structure of the source files, the compilation of the source files, and the conversion of the output to a desired format. Furthermore, many TEX users often desire to create 2D and 3D graphs of functions for inclusion into their d...

متن کامل

Literate Proving: Presenting and Documenting Formal Proofs

Literate proving is the analogue for literate programming in the mathematical realm. That is, the goal of literate proving is to produce clear expositions of formal mathematics that could even be enjoyable for people to read whilst remaining faithful representations of the actual proofs. This paper describes maze, a generic literate proving system. Authors markup formal proof files, such as Miz...

متن کامل

TEX to HTML and back

Both LTEX and HTML are languages that can express the structure of a document, and similarities between these two systems are shown. A detailed study is made of the LaTeX2HTML program, written by Nikos Drakos, that is today the most complete utility for translating LTEX code into HTML, providing a quasi-automatic translation for most elements. A discussion of a few other tools for translating b...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2011