Adobe 22020737 Acrobat X Pro Manual - Page 226

When are security warnings displayed?, Content security

Page 226 highlights

USING ACROBAT X PRO 220 Security When are security warnings displayed? Security warnings can be displayed in the following situations: Blacklisted JavaScript JavaScript is a computer language in widespread use. JavaScript code can be vulnerable to attacks, and JavaScript can be used to open websites. Adobe regularly updates the blacklist with known JavaScript vulnerabilities. If a PDF tries to access blacklisted JavaScript, you see a message in the yellow document bar, at the top. For administrators: • For instructions on how to manage JavaScript execution, see the article "JavaScript" on page 218 • For more information about the situations that trigger JavaScript warnings, see the TechNote at go.adobe.com/kb/ts_cpsid_50432_en-us. • For more information about blacklisted JavaScripts, see the TechNote at go.adobe.com/kb/ts_cpsid_50431_en-us. Security settings updates Adobe periodically distributes certificates for security purposes. These downloads help ensure that digitally signed PDFs from trusted sources maintain their trusted status. If you receive an update from an unknown source, verify that it is from a web address that you trust before proceeding. Updates from untrusted websites can create vulnerabilities on your computer. Accessing stream objects (XObjects) Acrobat and Reader display a warning when a PDF attempts to access external content identified as a stream object. For example, a URL might point to an external image. The silent transmission of data can pose a security risk as Acrobat and Reader communicate with an external source. Inserting data into PDFs and forms A warning appears when an untrusted source attempts to add data to a PDF form. Although this data-injection feature can streamline workflows in your organization, it can also be used to add malicious data into a PDF. Silent printing Silent printing is printing to a file or printer without your confirmation. It is a potential security risk because a malicious file can silently print multiple times to your printer, wasting printer resources. It can also prevent other documents from printing by keeping the printer busy. Contact your system administrator to determine when to allow silent printing. Web links In addition to visible web links in a PDF document, form fields can contain hidden JavaScript that open a page in a browser or silently request data from the Internet. Important: Acrobat and Reader X, 9.3, and 8.2 enable enhanced security by default. Adobe recommends that you enable enhanced security if it is not already enabled, and bypass restrictions only for trusted content. More Help topics "Enhanced security" on page 214 "Document message bar" on page 10 "Play multimedia" on page 361 "Multimedia Trust preferences" on page 362 Content security Content security includes features such as digital signatures, encryption, and permissions that ensure data integrity. Last updated 10/11/2011

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496

220
USING ACROBAT X PRO
Security
Last updated 10/11/2011
When are security warnings displayed?
Security warnings can be displayed in the following situations:
Blacklisted JavaScript
JavaScript is a computer language in widespread use. JavaScript code can be vulnerable to
attacks, and JavaScript can be used to open websites. Adobe regularly updates the blacklist with known JavaScript
vulnerabilities. If a PDF tries to access blacklisted JavaScript, you see a message in the yellow document bar, at the top.
For administrators:
For instructions on how to manage JavaScript execution, see the article “
JavaScript
” on page
218
For more information about the situations that trigger JavaScript warnings, see the TechNote at
go.adobe.com/kb/ts_cpsid_50432_en-us
.
For more information about blacklisted JavaScripts, see the TechNote at
go.adobe.com/kb/ts_cpsid_50431_en-us
.
Security settings updates
Adobe periodically distributes certificates for security purposes. These downloads help
ensure that digitally signed PDFs from trusted sources maintain their trusted status. If you receive an update from an
unknown source, verify that it is from a web address that you trust before proceeding. Updates from untrusted websites
can create vulnerabilities on your computer.
Accessing stream objects (XObjects)
Acrobat and Reader display a warning when a PDF attempts to access external
content identified as a stream object. For example, a URL might point to an external image. The silent transmission of
data can pose a security risk as Acrobat and Reader communicate with an external source.
Inserting data into PDFs and forms
A warning appears when an untrusted source attempts to add data to a PDF form.
Although this data-injection feature can streamline workflows in your organization, it can also be used to add
malicious data into a PDF.
Silent printing
Silent printing is printing to a file or printer without your confirmation. It is a potential security risk
because a malicious file can silently print multiple times to your printer, wasting printer resources. It can also prevent
other documents from printing by keeping the printer busy.
Contact your system administrator to determine when to allow silent printing.
Web links
In addition to visible web links in a PDF document, form fields can contain hidden JavaScript that open a
page in a browser or silently request data from the Internet.
Important:
Acrobat and Reader X, 9.3, and 8.2 enable enhanced security by default. Adobe recommends that you enable
enhanced security if it is not already enabled, and bypass restrictions only for trusted content.
More Help topics
Enhanced security
” on page
214
Document message bar
” on page
10
Play multimedia
” on page
361
Multimedia Trust preferences
” on page
362
Content security
Content security includes features such as digital signatures, encryption, and permissions that ensure data integrity.