Microsoft admits it can’t stop Office file format hacks

reghakr

New member
Local time
6:43 AM
Messages
1,614
Location
Pennsylvania
Microsoft admits it can’t stop Office file format hacks

Microsoft’s plan to “sandbox” Office documents in the next version of its application suite is an admission that the company cannot keep hackers from exploiting file format bugs, a security analyst said on July 23. “What’s been happening is that Office has lots of vulnerabilities,” said Gartner’s primary security analyst. “For the past 18 months, hackers have been fuzzing Office file formats,” he said, referring to the practice of “fuzzing,” a tactic that relies on automated tools that drop random data into applications to see if, and where, breakdowns occur. Fuzzing has been a hacker’s best friend: Microsoft has repeatedly had to patch file format vulnerabilities in Office applications, most recently in July when it fixed a flaw in Publisher 2007 and in June, when it patched seven vulnerabilities in Excel and two more in Word. “What’s happening is that the bad guys are using fuzzing tools to find vulnerabilities in Office, and now Microsoft is saying, ‘Okay, we can’t find, let alone fix, every vulnerability. So here’s a way to put a sandbox around the vulnerability.” The sandbox technique mentioned is a new addition to Office 2010, the upcoming upgrade to Microsoft’s bestselling Windows application suite. According to a senior security program manager with the Office team, Office 2010 will sport something called “Protected View” that isolates Word, Excel and PowerPoint files in a read-only environment. The sandbox, said the program manager in a post to a company blog this week, will have “minimal access to the system, and no access to your other files and information. Even if the file is malicious, it can’t get out of the sandbox and do harm to your computer or data.”

More.....
 

My Computer My Computer

Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
Welcome back!
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
First impressions seem good. Hope it won't be a resource hog and slow everyting down a lot!
 

My Computer My Computer

OS
Windows XP SP3
CPU
C2D E7300
Motherboard
Asus p5b-e plus
Memory
2x 1 gb OCZ ddr2800 CL4
Graphics Card(s)
radeon x1900xt
Sound Card
integrated
Monitor(s) Displays
15" tft
Hard Drives
Samsung Spinpoint F1 1TB
PSU
450W Arctic cooling
Case
Arctic cooling silentium eco 80
Cooling
Arctic freeze xtreme
Mouse
Logitech mx510
Internet Speed
8/1 Mbit
Welcome back!

Thanks,

I've been told I can't post the cyber security messages that do not apply to Microsoft or Windows 7:(
 

My Computer My Computer

Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
well this is a MS OS oriented forum...;)
and by the looks of it, it does seem like a nice addition (i think of it as another layer for people to try to bypass)...;)
of course there will be vulnerabilities in this too (i also think of java when i think sandboxing and its vulnerabilities...)
but again this will make it harder which i like...:)
 

My Computer My Computer

Computer Manufacturer/Model Number
Tx2500z Tablet Pc/Homemade Server
OS
Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
CPU
Turion X2 ultra (oh well came with laptop)/P4 @3.2 (yes P4)
Motherboard
IDK HP Motherboard / Intel DG965SS
Memory
OCZ Dual Channel 4GB kit/ 1gb Dual Channel
Graphics Card(s)
HD 3200 graphics /GMA x3100 (yay for intergrated!!)
Sound Card
Realtek HD Audio(mic working, well sort of)/Siig IC-70012
Monitor(s) Displays
built-in Hp 12" laptop screen/ Acer 19"
Screen Resolution
1280x800 /1440x900
Cooling
All Air Cooled
Mouse
Logi MX Rev. /MS Wheel Optical 1.1A /Logitech Optical Mouse
Internet Speed
College baby but its still routed through vpn to 1536k...
Other Info
love my wacom pen and pressure sensitivity...
wished it worked in 7, SUSE for that matter though
Back
Top