Microsoft admits it can’t stop Office file format hacks


  1. Posts : 1,614
    Windows 7 Pro & Vista Home Premium
       #1

    Microsoft admits it can’t stop Office file format hacks


    Microsoft’s plan to “sandbox” Office documents in the next version of its application suite is an admission that the company cannot keep hackers from exploiting file format bugs, a security analyst said on July 23. “What’s been happening is that Office has lots of vulnerabilities,” said Gartner’s primary security analyst. “For the past 18 months, hackers have been fuzzing Office file formats,” he said, referring to the practice of “fuzzing,” a tactic that relies on automated tools that drop random data into applications to see if, and where, breakdowns occur. Fuzzing has been a hacker’s best friend: Microsoft has repeatedly had to patch file format vulnerabilities in Office applications, most recently in July when it fixed a flaw in Publisher 2007 and in June, when it patched seven vulnerabilities in Excel and two more in Word. “What’s happening is that the bad guys are using fuzzing tools to find vulnerabilities in Office, and now Microsoft is saying, ‘Okay, we can’t find, let alone fix, every vulnerability. So here’s a way to put a sandbox around the vulnerability.” The sandbox technique mentioned is a new addition to Office 2010, the upcoming upgrade to Microsoft’s bestselling Windows application suite. According to a senior security program manager with the Office team, Office 2010 will sport something called “Protected View” that isolates Word, Excel and PowerPoint files in a read-only environment. The sandbox, said the program manager in a post to a company blog this week, will have “minimal access to the system, and no access to your other files and information. Even if the file is malicious, it can’t get out of the sandbox and do harm to your computer or data.”

    More.....
      My Computer


  2. Posts : 11,840
    64-bit Windows 8.1 Pro
       #2

    Welcome back!
      My Computer


  3. Posts : 14
    Windows XP SP3
       #3

    First impressions seem good. Hope it won't be a resource hog and slow everyting down a lot!
      My Computer


  4. Posts : 1,614
    Windows 7 Pro & Vista Home Premium
    Thread Starter
       #4

    Tews said:
    Welcome back!
    Thanks,

    I've been told I can't post the cyber security messages that do not apply to Microsoft or Windows 7
      My Computer


  5. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #5

    well this is a MS OS oriented forum...
    and by the looks of it, it does seem like a nice addition (i think of it as another layer for people to try to bypass)...
    of course there will be vulnerabilities in this too (i also think of java when i think sandboxing and its vulnerabilities...)
    but again this will make it harder which i like...:)
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:22.
Find Us