RE: More Office XP problems

From: Mary Landesman (mlandeat_private)
Date: Sat Apr 06 2002 - 12:48:53 PST

  • Next message: Nick Lamb: "Re: VNC Security Bulletin - zlib double free issue (multiple vendors and versions)"

    This could well be considered risky behavior. A .DOC file containing macros
    can be renamed to .RTF. Word will quite happily open and execute the macros
    in these files. (One of the Melissa variants took advantage of this).
    Getting people used to practices that have inherent weaknesses in them leads
    to a false sense of security and, IMO, a greater risk of infection. RTF fits
    that bill all too well.
    
    -- Mary Landesman
    
    -----Original Message-----
    From: Kevin Brown [mailto:kevinat_private]
    Sent: Friday, April 05, 2002 8:57 PM
    To: 'BUGTRAQat_private'
    Subject: RE: More Office XP problems
    
    
    RTF is a benign file format and does not support scripting or embedded HTML
    tags.  I know of large companies that require all external documents be sent
    to them as RTF to avoid the problems of macro viruses and other malicious
    code.
    
    Brownfox
    
    
    -----Original Message-----
    From: Paul Schmehl [mailto:paulsat_private]
    Sent: Friday, April 05, 2002 6:36 PM
    To: Leonard Chung; guninskiat_private; Ben Schorr
    Cc: 'BUGTRAQat_private'
    Subject: RE: More Office XP problems
    
    
    The default editor for Outlook XP (2002) is Word *if*
    Office is installed.  (I don't know if it is if Office
    isn't installed.)  Default "sending type" is RTF.
    {{shudder}}
    



    This archive was generated by hypermail 2b30 : Mon Apr 08 2002 - 20:35:20 PDT