BoutonJones.com

Hacking Redacted PDFs (Video)

A brief demonstration on how to "hack" PDFs that appear to be redacted. It explains why is it possible to hack some PDFs and not others. (2:13)

View on YouTube

Transcript:

I will now demonstrate how to hack a PDF that has not been properly redacted. First, I select the text that needs to be unredacted. Then, I press control C on my keyboard. This will copy the text. I open up Notepad. (That's a text editor that is part of Windows.) You can use any text editor to do this, but for simplicity's sake I'm going to use Notepad.
I hold down the Control key on my keyboard and press V. That pastes the text inside Notepad. Because Notepad is a text editor, it strips it [the text] of all visual formatting. This is purely text. And you'll notice that the "redacted" name appears here. Well, this document is not properly redacted.

Instead of redacting the document, this user masked the content. One way to mask --- and I'm talking about masking here not redacting --- Is just select the text --- that's a black text on a white background --- and change the background to black. Another method is to insert a shape over the object.

Again, this is not redacting the document. It's just covering the text with the shape, another layer. The text layer is unaffected. It still can be retrieved. It can be copied and pasted in either of these situations. Whether you have a black background or if you're masking the text, the text that you meant to redact is still there.

You can copy and paste it. You can also run a screen reader and it would read the text unimpeded with no indication that it's meant to be redacted.