Bugtraq mailing list archives
Re: Microsoft Office security bug
From: aleph1 () DFW NET (Aleph One)
Date: Tue, 11 Nov 1997 21:44:57 -0600
On Tue, 11 Nov 1997, Inigo Gonzalez wrote:
I am no expert on Win32 / OLE-COM-ACtiveX; but it seems that this isn't Office Fault; but OLE one's. AFAIK, every OLE container is responsible of its own data; in this case, you tell Word to cipher his own data, and Excel/Visio/etc... data is not Word bussiness so it's not ciphered. Remember: When you talk to OLE objects, you delegate them a part of your file + archiving capabilities.
Your are correct. But it matters little. The users expectation is that all of the document will be encrypted, including any embeded objects. Obviously this is not the case. How would you feel if you found out that that your Netscape or IE browser only encrypted the body of email messages using S/MIME but not any attachments? Aleph One / aleph1 () dfw net http://underground.org/ KeyID 1024/948FD6B5 Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01
Current thread:
- Re: Intel Pentium Bug, (continued)
- Re: Intel Pentium Bug Joe Ilacqua (Nov 07)
- Re: Intel Pentium Bug Rubens Kuhl Jr. (Nov 07)
- Re: Intel Pentium Bug Ralf Baechle (Nov 10)
- Re: Intel Pentium Bug Barry Irwin (Nov 08)
- Re: Intel Pentium Bug Bjorn Wesen (Nov 08)
- Re: Intel Pentium Bug Peter Bierman (Nov 08)
- Re: Intel Pentium Bug Aleph One (Nov 08)
- Microsoft Office security bug Aleph One (Nov 07)
- Re: Microsoft Office security bug Inigo Gonzalez (Nov 11)
- What were the opcodes to hang a Pentium again? (fwd) Darren Reed (Nov 11)
- Re: Microsoft Office security bug Aleph One (Nov 11)
- Vunerability in Lizards game SUID (Nov 11)
- Re: Vunerability in Lizards game Alex Murray (Nov 12)
- Re: Vunerability in Lizards game Olaf Titz (Nov 13)
- Re: Vunerability in Lizards game Kragen \ (Nov 13)
- Re: Vunerability in Lizards game Neil Levine (Nov 17)
- Re: Vunerability in Lizards game Joe Zbiciak (Nov 18)
- Re: Vunerability in Lizards game Zoltan Hidvegi (Nov 18)
- Major Security Flaw in Cybercash 2.1.2 Kerri Kraft (Nov 19)
- IP DOS attacks -- Win95 and WinNT Paul Leach (Nov 18)
- Microsoft Office security bug Aleph One (Nov 07)
- Updating microcode on the fly Superuser (Nov 12)