PDF Security Test Sets

Files that exercise security-critical PDF features: embedded JavaScript, hidden content, injection vectors, and resource-exhaustion constructs. For validating sanitizers, sandboxes, and content filters.

js-open-action.pdf · /JS STUB · AUTHORIZED USE ONLY

01WHAT'S IN THE PACK

What's in the Pack

security-test-pack.zip contains:

  • js-open-action.pdf/OpenAction with a JavaScript stub that calls app.alert(). Purpose: verify that viewers block or sandbox JS execution.
  • js-embedded-script.pdfEmbedded /JS stream with a no-op script. Purpose: test JS extraction and static-analysis tooling.
  • hidden-text.pdfWhite-on-white text and zero-width text positioning. Purpose: verify that text-extraction and sanitization tools surface hidden content.
  • injection-payload.pdf/URI and /Launch annotations containing shell-command-like strings (inert). Purpose: test annotation sanitization.
  • bloated-object.pdfA single PDF object exceeding 50 MB of nested arrays. Purpose: test memory-limit enforcement and DoS resilience.
  • AUP.txtAcceptable Use Policy (full text below).
  • README.mdPer-file: payload type, expected sanitizer behavior, ISO 32000 clauses.

02ACCEPTABLE USE POLICY (AUP)

Acceptable Use Policy

ACCEPTABLE USE POLICY — SECURITY TEST FILES

1. Scope: These files are for authorized software testing only. "Authorized" means you
   own the system under test or have explicit written permission from its owner.

2. Not weapons: The payloads are structural stubs, not functional exploits. They do not
   execute code, exfiltrate data, or compromise systems. Do not modify them to create
   functional exploits.

3. Isolation: Open these files only in sandboxed or disposable environments. Do not open
   them on production systems or in PDF viewers connected to sensitive data.

4. Legal compliance: You are responsible for complying with all applicable computer-misuse,
   cybersecurity, and data-protection laws in your jurisdiction.

5. No redistribution of modified files: You may share the unmodified ZIP. Do not
   redistribute modified or enhanced versions of these files.

6. Liability: ExamplePDF provides these files "as is" and accepts no liability for damage,
   data loss, or legal consequences arising from their use. See Terms of Service Section 7.

By downloading security-test-pack.zip, you confirm that you have read and agree to this AUP.

03DOWNLOAD

Download

I Agree — Download security-test-pack.zip BY CLICKING, YOU CONFIRM YOU HAVE READ AND ACCEPT THE AUP ABOVE.

No. They contain structural stubs (JavaScript no-ops, hidden text, inert URI strings, oversized objects) that test whether your software handles these features safely. They are not functional exploits and do not execute code or exfiltrate data.

Security engineers, QA teams, and developers testing PDF parsers, viewers, content filters, or sanitization pipelines. You must own or be authorized to test the target systems.

Only for testing defensive tooling (sanitizers, sandboxing) on systems you own or are authorized to test. Do not use them offensively against third-party systems.