Bonum Certa Men Certa

Taking Microsoft OOXML to Task

Any Windows/Office debuggers in the audience?

The following is a reproduction of a new post from Rex Ballard (I started this discussion thread), whose previous post we quoted the other day.




Message-ID: <31a66169-d9e7-4715-9e9e-e3488ebd36a9@25g2000hsx.googlegroups.com> From: Rex Ballard <rex.ballard@gmail.com> Newsgroups: comp.os.linux.advocacy Subject: Re: Leaked ISO Document Reveals Crooked ISO Amid MS OOXML Corruptions Date: Sat, 12 Jul 2008 08:20:23 -0700 (PDT)

[...]

ODF is a comprehensive document that provides detailed specifications from the high level document content down to the smallest elements of scalable vector graphics. There are some "standard" mime object types that are supported, such as PNG and JPEG, but other embedded formats must be installed using plug-ins which have to be authenticated by the user and by the system at installation time, and cannot be installed by the content. Furthermore, the installed content can easily be identified as trustworthy or not, and can be restricted in it's capabilities.

OpenXML on the other hand, is a high-level specification which describes the high level envelopes used to embed binary objects which are included in the content. The content itself contains the binary code which can call any function in any Microsoft library and has all permissions of the person opening the document. If a user account is set up as "Administrator", then the application can mess with the registry, create, download, and hide files, can execute applications in those files, can install any number of new viruses, and generally wreak havoc on the system.

I'll leave it to others to document the exact details (as I said, I'm busy these days), but I'm sure anyone who tries to publish these vulnerabilites will probably find themselves getting the same treatment that Tracy Reed of Ultraviolet.org got when he tried to publish his warnings about ActiveX controls back in 1997. Microsoft got a court injunction against him, and forced him to take down the content, claiming that it was being used to encourage hacking, and was damaging the Microsoft brand.

“I got a couple of docx documents and had trouble getting them to open, even with the plug-in for Office XP. Next thing I know, I get a notice from my registry auditor that I have 1300 new registry errors.”Over the last 10 years, we've seen these very same techniques, documented back in 1997, used widely to spread viruses including Melissa, Nimda, Sky, BugBear, and about 250,000 other viruses, worms, and malware, not including spy-ware and other "Microsoft Authorized" invasions of our privacy.

I got a couple of docx documents and had trouble getting them to open, even with the plug-in for Office XP. Next thing I know, I get a notice from my registry auditor that I have 1300 new registry errors. And suddenly, my PC is churning the disk-drive and the network connection at 3:00 AM (I'm getting old and have to get up), and the network shows that I'm uploading something at full speed, even though my computer is supposedly sleeping.

It isn't a back-up program that I'm running.

I would encourage COLA readers and OSS advocates to explore this in more detail.

get someone with Office 2007 to send you a docx file. unzip it using pkzip or winzip or unzip.

look at the binary files.

replace one binary object with another.

zip up the document,

see if your office-2007 user can read the "enhanced" document.

For those of you with OLE programming skills, create an OLE object that creates a file, and e-mails that file to you using smtp.

Send a document with this new ole object embedded (along with the others) and see if you get an e-mail.

I haven't tried this, and I don't know if it will work. I'm not sure how hard it would be to make it work. I just think it might be an interesting project worth investigating, especially if you are considering the migration of a few thousand users to Vista and Office 2007.

I'd love to see what the results turn out to be. After all, if it's that easy to take control of a recipient's machine just by sending them a "trusted" Word, Excel, or PowerPoint attachment, just think how much chaos a really aggressive malicious hacker, with a goal of obtaining marketable information about your business, could do.




Does ISO really want to approve such a 'virus'? As an international standard even? If someone tests the above, please post the outcome here or elsewhere. It would prove invaluable.

The last time a chain of ISO problems was cited, Ian Easson challenged an argument from Groklaw. He might wish read the following lengthy follow-up. ISO is in a deeper puddle of mud than before.

Brazil is a P member of SC 34, so according to my reading of the clause, it has the right to appeal if any of the three above issues apply, and arguably they all do. According to South Africa, if the issue is ISO's reputation, or if there is a matter of principle involved, Brazil can appeal. Even point three could apply, in that Brazil raises matters such as incorrect tabulation of votes, which, if true, one would hope ISO wasn't aware of.

[...]

Why did they bother to go, one might ask? Why vote, if votes disappear from the record? By my reading, Brazil paints a picture of an orchestrated event, tilted away from criticism or a negative result and a refusal to give substantive consideration to issues delegates wanted to discuss, due to time constraints Brazil calls arbitrary, and worse.


For details about the BRM in question, see [1, 2, 3, 4, 5, 6, 7, 8] and have your jaw sink to the floor. It was a bad plan from the get-go [1, 2, 3, 4, 5], but Emperor Microsoft was in a hurry and it even used its lobbyist Jan Van Den Beld to change the rules 'on the fly'.

OOXML protests in India
From the Campaign for Document Freedom

Recent Techrights' Posts

The "Luddite" Complex
Sometimes simplest is best and sometimes "modern" is designed not with the buyers' interest in mind
SCO's Darl McBride Dead at Age 64
There's hardly any information about it, except we know he reached bankruptcy and 3 years later he died at a relatively young age
[Meme] Python Knows Its Bosses
Microsoft strings attached
[Meme] Debt of About $20 Per Active User
Facebook isn't laying off tens of thousands for "efficiency" but for survival
 
Links 02/11/2024: Many Fakes in Social Control Media
Links for the day
GNU/Linux Usage Surveys: Up to 6.8% (With ChromeOS, Based on StatCounter) in Desktops/Laptops and Above 2% in Steam
Today StatCounter starts releasing graphs based on data for November
Gemini Links 02/11/2024: Petscop, Jokes, and RetroChallenge
Links for the day
Links 02/11/2024: Temu EU Probe and Shorts Trademark
Links for the day
The 'Turning-Free-Code-Proprietary Foundation' (Linux/Microsoft Foundation)
LF will basically become just as sinister as its corporate sponsors
Python Software Foundation is 'Cancel Culture' Rehomed
Python isn't grassroots and it doesn't really tolerate grassroots
DeVault "Closes Down His Mailing Lists Every Time There's a Scandal" and Also Censors Messages
Censorious code hosting platform
What Social Control Media Really Is
Social Control Media, in a nutshell, isn't just bad if its controller is some foreign or hostile nation
Taking Ethics Lectures From Drew
Projection tactics
Links 02/11/2024: Facebook Stock Falls (Soaring Debt), Apple’s Quarterly Profit Down
Links for the day
Gemini Links 02/11/2024: Burnout, Emacs Bookmarks, and Smooth Migration
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, November 01, 2024
IRC logs for Friday, November 01, 2024
Facebook's Debt Has Soared to All-Time High of Nearly 50 Billion Dollars
But the corporate media pretends all is well (while mass layoffs continue and slop takes over the social control media)
Geminispace Makes It Past 4,200 Capsules on November 1st
At last!
Links 01/11/2024: Election Interferences by X/Twitter/Musk, Strava as Espionage Tool
Links for the day
The October 2024 Web Server Survey Shows a Further Collapse for Microsoft in the Servers Market
Microsoft experienced the next largest loss of 699,464 sites (-3.45%)
Gemini Links 01/11/2024: TLS Sucks, twytere.com Announced
Links for the day
Links 01/11/2024: Few Things Are Cheaper Than This Antenna and "Nothing Lasts Forever"
Links for the day
Technology: rights or responsibilities? - Part V
By Dr. Andy Farnell
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, October 31, 2024
IRC logs for Thursday, October 31, 2024
R.T.O. is Another Name (or Acronym) for Voluntary Layoffs
Amazon is trying to get many workers to leave on their own
Microsoft's Acquisition of Activision (to Fake Revenue Growth by Buying Revenue) Was a Failure
Of course the mass layoffs at Microsoft aren't just a Microsoft thing
Stagnant, Shrinking Businesses and "IBM's Corporate Culture Since the Late 1980s... Over 35 Years."
Recently, IBM was using share price as a talking point, insisting the company was doing OK while tens of thousands were being laid off
Links 01/11/2024: World News, Political Catchup
Links for the day
[Meme] Probably the Worst Possible Time to Get Information From Social Control Media
Musk does not want to prevent disinformation from spreading and the same is true for Facebook and TikTok; they have their own interests
Update on Litigation Against the European Patent Office (EPO) at the ILO Administrative Tribunal (ILOAT)
Rewards and compensation for staff have long fallen, resulting in many experienced colleagues leaving and causing further declines in quality and compliance
Gemini Links 31/10/2024: NNCP, Declutter the Web, Cost of Community
Links for the day
Links 31/10/2024: Supermicro Plummets 33%, Block and Dropbox Mass Layoffs
Links for the day
Links 31/10/2024: Environmental Anxiety, Profound Changes in Hardware Market
Links for the day
Links 30/10/2024: TSMC Concerns and North Koreans in Ukraine War
Links for the day
Facebook is for Zombies
Social control media is for fools
Microsoft Now Has $235,290,000,000 in Liabilities, They Grow Over Time in Spite of Mass Layoffs (So Expect More Layoffs)
expect more mass layoffs
Links 31/10/2024: DST Woes, War Updates, Amazon RTO Backlash
Links for the day
Gemini Links 31/10/2024: Attention Economy and Gemlogs
Links for the day
Happy Halloween
October is nearly over
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, October 30, 2024
IRC logs for Wednesday, October 30, 2024
For the Record: Linux is Controlled by the United States of America
"This is going to make many question the openness and inclusivity of the work done by Linux Foundation"
Microsoft: XBox Hardware Revenues Down About 30% (Ignore the Buzzwords and Activision Activity Dressed Up as "XBox")
For context, in a previous quarter XBox hardware sales were down by about 50%
Cooking the Books With "Cloud" And "AI" Was Not Enough to Fool Microsoft Investors
"Microsoft Shares Drop on Disappointing Azure Growth Forecast"