Postscript Pat and His Black and White Hat

No ratings

Presented at BlueHatIL 2019 by

This talk details the approach taken to target Postscript engines (Adobe Distiller & Ghostscript) for the discovery of zero-day vulnerabilities. What is Postscript? How do the engines differentiate in parsing Postscript? Why haven’t these engines been targeted as heavily as other scripting engines? Details regarding the design of a custom fuzzer and auditing methodology will be demonstrated and shared including *some* details of already discovered zero-day vulnerabilities.