5 ms·
Given there are two prompts that the document is trying to do something "different", and the second tells you explicitly it's trying to run an executable and pr
by jonathonf 9y ago
Given there are two prompts that the document is trying to do something "different", and the second tells you explicitly it's trying to run an executable and provides a path, is this realistically exploitable?
- Gaelan 9y agohttps://i.imgur.com/H0uVqFer.jpg https://i.imgur.com/H0uVqFer.jpg
- jononor 9y agoFrom observing users, it seems that just clicking OK without even reading dialog prompts seems quite common..
- wlesieutre 9y agoEven if you've specifically asked that next time it happens they stop and read you the error, they'll click OK and text you "There was an error can you fix it?"
- Tijdreiziger 9y agoFurther down in the post, they explain how you can use a different syntax to get a non-suspicious prompt.
- est 9y agoGiven that only 1% chances of people click OK, you just spam it to millions of people. Someone will click OK.
- rightos 9y agoBut then it's really not much better than spamming a .ps1 or .js script (handled by Windows Script Host by default), or even straight up executable as many already do. If they're at that level then there's really not much you can do but avoid having them get the stuff in the first place.
- ec109685 9y agoThose can be filtered by email systems.
- deleted 9y ago[deleted]
- rightos 9y agoSo can this, it'd be fairly trivial to detect and block anything using DDE at the file level - however a common strategy is to send an encrypted archive file and give the password in the email to bypass that detection. Trashing all encrypted archives automatically.... ehh, maybe viable?
- zxcmx 9y agoThe other scenario where this kind of thing can be useful is poorly secured "kiosks", aka, you want to run arbitrary code but the administrator of that machine doesn't want you to. Macros can be disabled by group policy.
- tinus_hn 9y agoIt doesn’t even come with red text and warning signs. Users don’t read this stuff and even if they do, it’s easy to explain the warnings away in the document or the email that contains it. It is just stupid design and there is no excuse this is still in a supported application in 2017. But then again, what would you expect from Microsoft Office.