ทำความสะอาด PDF
ลบ JavaScript ไฟล์ที่ฝังไว้ และการกระทำที่ทำงานตอนเปิดไฟล์
เครื่องมือนี้ทำงานในเบราว์เซอร์ของคุณทั้งหมด ไฟล์ของคุณไม่ถูกอัปโหลดเลย และคุณตรวจสอบได้เองในแท็บเครือข่ายของเบราว์เซอร์ ตรวจสอบด้วยตัวเอง เปิดแท็บเครือข่ายของเบราว์เซอร์แล้วดู คุณจะเห็นคำขอเล็ก ๆ หนึ่งรายการที่ถามว่าคุณยังมีโควตางานเหลืออยู่หรือไม่ ซึ่งมีแค่ชื่อเครื่องมือกับค่าแฮช ไม่ใช่ตัวไฟล์
เครื่องมือนี้ทำอะไร
A PDF is not a static document. It can carry JavaScript, run an action the moment it is opened, hold other files inside itself, and send a reader out to a URL. Those features have legitimate uses, and they are also why PDFs are a common malware carrier. This tool rebuilds the document from its pages alone, which leaves every document-level hook behind.
Use it on anything that arrived unexpectedly and has to be read anyway: an invoice from an address you do not recognise, a CV from a job board, a form downloaded from a site you have no reason to trust. It is also worth running on files you distribute, so nobody has to wonder whether the attachment inside yours is meant to be there.
วิธีทำงาน
- Drop the PDF onto this page.
- Leave the three main switches on. JavaScript, embedded files and open actions are all served by one rebuild, and together they cover nearly everything active a PDF can carry.
- Turn on Remove external links if the file came from a source you do not trust, since a link is a phishing vector even when nothing else in the file is.
- Turn on Strip metadata under advanced options if you also want the author and timestamps gone.
- Press Sanitize. The result reports the page count and how many embedded files were removed.
The removal works by not copying rather than by deleting. The document is rebuilt into an empty file with only its pages carried over, so document-level JavaScript, the name tree of embedded files, the action that fires on open and the rest are never brought across at all. That is more reliable than hunting through a file for each hook: you cannot forget to remove something you never copied.
Because it is one rebuild, the first three switches are effectively one decision. Turning any of them on rebuilds the document, and the rebuild leaves all of them behind. They are separate controls because they name separate worries, not because you can keep the JavaScript and lose the attachments.
The rebuild is thorough enough to cost you things you may want. Document-level structure is exactly what is discarded, so the interactive form dictionary, the outline and anything else attached to the document rather than to a page does not survive. A fillable form comes out as pages that look right and no longer fill in. That is why you should sanitise files you receive rather than files you are still working on.
A file attached as a page annotation is not in the name tree, so the rebuild alone would leave it in place. Attachments are counted before the rebuild and removed by name afterwards, which catches both kinds. The number in the result is what was actually found, so a report of zero embedded files is information rather than a shrug.
This runs entirely in your browser on qpdf compiled to WebAssembly. For a file you already suspect, that is the right shape: the document is never handed to a third party, and it is never opened by a full PDF reader with scripting enabled - qpdf parses the structure without executing anything in it.
สิ่งที่เครื่องมือนี้ทำไม่ได้
- This is not antivirus software. It removes the categories of active content a PDF can hold; it does not scan for or identify malware, and it cannot tell you whether a file was hostile.
- The rebuild discards document-level structure, so a fillable form stops being fillable and the outline is not carried over.
คำถามที่คนมักถาม
- อะไรนับเป็นเนื้อหาที่ทำงานได้ใน PDF
- JavaScript ระดับเอกสาร ซึ่งโปรแกรมอ่านอาจรันให้อัตโนมัติ OpenAction ที่ทำงานทันทีที่เปิดไฟล์ พร้อมกับตัวกระตุ้นแบบเดียวกันเมื่อเปลี่ยนหน้าและเมื่อเกิดเหตุการณ์ในฟอร์ม ไฟล์ที่ฝังอยู่ภายใน PDF และลิงก์หรือการกระทำที่ติดต่อออกไปยัง URL ทั้งหมดนี้เป็นคุณสมบัติที่ถูกต้องตามมาตรฐาน และเป็นวิธีมาตรฐานที่ PDF ถูกใช้เป็นตัวนำส่งสิ่งไม่พึงประสงค์ด้วยเช่นกัน
- เครื่องมือนี้ลบไวรัสออกจาก PDF ได้หรือไม่
- มันลบส่วนของ PDF ที่สามารถพาและเปิดใช้ไวรัสได้ ซึ่งไม่เหมือนกับการสแกนหามัลแวร์และไม่ควรถือว่าเป็นสิ่งเดียวกัน หากคุณมีเหตุผลจริงจังที่คิดว่าไฟล์เป็นอันตราย อย่าเปิดมัน ให้ใช้ซอฟต์แวร์แอนตี้ไวรัส หรือถามผู้ส่งผ่านช่องทางที่คุณเชื่อถือ การทำความสะอาดลดสิ่งที่เอกสารทำได้ แต่ไม่ใช่คำตัดสินว่าเอกสารปลอดภัย
- อะไรอาจใช้งานไม่ได้หลังจากนี้
- ทุกอย่างที่ขึ้นกับตัวเอกสารมากกว่าตัวหน้า ฟอร์มที่กรอกได้จะรับข้อมูลไม่ได้อีก สารบัญบุ๊กมาร์กจะไม่ถูกนำติดไปด้วย ไฟล์แนบที่ฝังไว้จะหายไป และฟอร์มที่คำนวณยอดรวมด้วย JavaScript จะแสดงเฉพาะค่าที่บันทึกไว้ล่าสุด ส่วนเนื้อหาของหน้า ข้อความ และภาพจะไม่เปลี่ยนแปลง
- ควรลบลิงก์ภายนอกด้วยหรือไม่
- ตัวเลือกนี้ปิดไว้โดยค่าเริ่มต้น เพราะลิงก์ส่วนใหญ่ในเอกสารส่วนใหญ่เป็นสิ่งที่ต้องการ และการลบออกจากรายงานที่คุณอ่านเองก็น่ารำคาญ ให้เปิดใช้กับไฟล์จากแหล่งที่คุณไม่ไว้ใจ ลิงก์ที่ดูเหมือนธนาคารที่คุ้นเคยแต่ชี้ไปที่อื่นคือกลลวงที่เก่าแก่ที่สุดในไฟล์ และการลบลิงก์ทุกอันเป็นคำตอบที่หยาบแต่ครบถ้วน
- ไฟล์ที่น่าสงสัยถูกอัปโหลดไปที่ใดหรือไม่
- ไม่ qpdf ทำงานเป็น WebAssembly ใน Web Worker ในเบราว์เซอร์ของคุณ และมันแยกวิเคราะห์โครงสร้างของไฟล์โดยไม่รันสิ่งใดที่อยู่ข้างใน ไฟล์ที่คุณไม่ไว้ใจอยู่แล้วจะไม่ไปถึงเซิร์ฟเวอร์ และไม่ถูกส่งต่อให้โปรแกรมอ่านที่เปิดสคริปต์ได้ระหว่างทาง