Làm sạch PDF
Loại bỏ JavaScript, tệp nhúng và các hành động chạy khi mở.
Công cụ này chạy hoàn toàn trong trình duyệt của bạn. Tệp của bạn không bao giờ được tải lên, và bạn có thể tự kiểm chứng điều đó trong tab mạng của trình duyệt. Tự kiểm chứng: mở tab mạng của trình duyệt và theo dõi. Bạn sẽ thấy một yêu cầu nhỏ hỏi xem bạn còn tác vụ nào không - một tên công cụ và một mã băm, không bao giờ là tệp.
Công cụ này làm gì
A PDF is not a static document. It can carry JavaScript, run an action the moment it is opened, hold other files inside itself, and send a reader out to a URL. Those features have legitimate uses, and they are also why PDFs are a common malware carrier. This tool rebuilds the document from its pages alone, which leaves every document-level hook behind.
Use it on anything that arrived unexpectedly and has to be read anyway: an invoice from an address you do not recognise, a CV from a job board, a form downloaded from a site you have no reason to trust. It is also worth running on files you distribute, so nobody has to wonder whether the attachment inside yours is meant to be there.
Cách hoạt động
- Drop the PDF onto this page.
- Leave the three main switches on. JavaScript, embedded files and open actions are all served by one rebuild, and together they cover nearly everything active a PDF can carry.
- Turn on Remove external links if the file came from a source you do not trust, since a link is a phishing vector even when nothing else in the file is.
- Turn on Strip metadata under advanced options if you also want the author and timestamps gone.
- Press Sanitize. The result reports the page count and how many embedded files were removed.
The removal works by not copying rather than by deleting. The document is rebuilt into an empty file with only its pages carried over, so document-level JavaScript, the name tree of embedded files, the action that fires on open and the rest are never brought across at all. That is more reliable than hunting through a file for each hook: you cannot forget to remove something you never copied.
Because it is one rebuild, the first three switches are effectively one decision. Turning any of them on rebuilds the document, and the rebuild leaves all of them behind. They are separate controls because they name separate worries, not because you can keep the JavaScript and lose the attachments.
The rebuild is thorough enough to cost you things you may want. Document-level structure is exactly what is discarded, so the interactive form dictionary, the outline and anything else attached to the document rather than to a page does not survive. A fillable form comes out as pages that look right and no longer fill in. That is why you should sanitise files you receive rather than files you are still working on.
A file attached as a page annotation is not in the name tree, so the rebuild alone would leave it in place. Attachments are counted before the rebuild and removed by name afterwards, which catches both kinds. The number in the result is what was actually found, so a report of zero embedded files is information rather than a shrug.
This runs entirely in your browser on qpdf compiled to WebAssembly. For a file you already suspect, that is the right shape: the document is never handed to a third party, and it is never opened by a full PDF reader with scripting enabled - qpdf parses the structure without executing anything in it.
Công cụ này không làm được gì
- This is not antivirus software. It removes the categories of active content a PDF can hold; it does not scan for or identify malware, and it cannot tell you whether a file was hostile.
- The rebuild discards document-level structure, so a fillable form stops being fillable and the outline is not carried over.
Câu hỏi thường gặp
- Cái gì được tính là nội dung động trong một PDF?
- JavaScript ở cấp tài liệu, thứ mà một trình đọc có thể chạy tự động; một OpenAction kích hoạt ngay khoảnh khắc tệp được mở, cùng với các trình kích hoạt tương đương khi chuyển trang và khi có sự kiện biểu mẫu; các tệp nhúng bên trong PDF; và các liên kết hay hành động vươn ra tới một URL. Tất cả đều là những tính năng hợp pháp nhưng cũng là những cách thông thường mà một PDF được dùng làm phương tiện phát tán.
- Việc này có gỡ vi-rút khỏi một PDF không?
- Nó loại bỏ những phần của một PDF có thể mang và khởi chạy vi-rút, việc này không giống với quét mã độc và không nên được xem như vậy. Nếu bạn có lý do thực sự để nghĩ một tệp là độc hại, đừng mở nó - hãy dùng phần mềm diệt vi-rút, hoặc hỏi người gửi qua một kênh bạn tin tưởng. Làm sạch giảm bớt những gì một tài liệu có thể làm; nó không phải là một phán quyết về tài liệu đó.
- Sau đó những gì có thể ngừng hoạt động?
- Bất cứ thứ gì phụ thuộc vào tài liệu chứ không phải vào một trang. Một biểu mẫu điền được sẽ ngừng nhận nhập liệu, mục lục dấu trang không được giữ lại, các tệp đính kèm nhúng biến mất, và một biểu mẫu tính tổng bằng JavaScript chỉ hiển thị các giá trị lưu gần nhất. Nội dung trang, văn bản và ảnh không thay đổi.
- Tôi có nên xóa cả các liên kết ngoài không?
- Mặc định tắt vì hầu hết liên kết trong hầu hết tài liệu là cần thiết, và loại bỏ chúng khỏi một báo cáo mà chính bạn đang đọc thì phiền phức. Hãy bật nó cho một tệp từ một nguồn bạn không tin cậy: một liên kết trông giống một ngân hàng quen thuộc nhưng lại trỏ đi nơi khác là chiêu trò xưa nhất trong tệp, và xóa mọi liên kết là một câu trả lời thô nhưng trọn vẹn cho nó.
- Tệp đáng ngờ có được tải lên đâu đó không?
- Không. qpdf chạy dưới dạng WebAssembly trong một Web Worker trong trình duyệt của bạn, và nó phân tích cấu trúc của tệp mà không thực thi bất cứ thứ gì bên trong. Một tệp bạn vốn đã nghi ngờ không bao giờ tới được một máy chủ, và nó không bao giờ bị giao cho một trình đọc bật kịch bản trên đường đi.