Bonum Certa Men Certa

Taking Microsoft OOXML to Task

Any Windows/Office debuggers in the audience?

The following is a reproduction of a new post from Rex Ballard (I started this discussion thread), whose previous post we quoted the other day.




Message-ID: <31a66169-d9e7-4715-9e9e-e3488ebd36a9@25g2000hsx.googlegroups.com> From: Rex Ballard <rex.ballard@gmail.com> Newsgroups: comp.os.linux.advocacy Subject: Re: Leaked ISO Document Reveals Crooked ISO Amid MS OOXML Corruptions Date: Sat, 12 Jul 2008 08:20:23 -0700 (PDT)

[...]

ODF is a comprehensive document that provides detailed specifications from the high level document content down to the smallest elements of scalable vector graphics. There are some "standard" mime object types that are supported, such as PNG and JPEG, but other embedded formats must be installed using plug-ins which have to be authenticated by the user and by the system at installation time, and cannot be installed by the content. Furthermore, the installed content can easily be identified as trustworthy or not, and can be restricted in it's capabilities.

OpenXML on the other hand, is a high-level specification which describes the high level envelopes used to embed binary objects which are included in the content. The content itself contains the binary code which can call any function in any Microsoft library and has all permissions of the person opening the document. If a user account is set up as "Administrator", then the application can mess with the registry, create, download, and hide files, can execute applications in those files, can install any number of new viruses, and generally wreak havoc on the system.

I'll leave it to others to document the exact details (as I said, I'm busy these days), but I'm sure anyone who tries to publish these vulnerabilites will probably find themselves getting the same treatment that Tracy Reed of Ultraviolet.org got when he tried to publish his warnings about ActiveX controls back in 1997. Microsoft got a court injunction against him, and forced him to take down the content, claiming that it was being used to encourage hacking, and was damaging the Microsoft brand.

“I got a couple of docx documents and had trouble getting them to open, even with the plug-in for Office XP. Next thing I know, I get a notice from my registry auditor that I have 1300 new registry errors.”Over the last 10 years, we've seen these very same techniques, documented back in 1997, used widely to spread viruses including Melissa, Nimda, Sky, BugBear, and about 250,000 other viruses, worms, and malware, not including spy-ware and other "Microsoft Authorized" invasions of our privacy.

I got a couple of docx documents and had trouble getting them to open, even with the plug-in for Office XP. Next thing I know, I get a notice from my registry auditor that I have 1300 new registry errors. And suddenly, my PC is churning the disk-drive and the network connection at 3:00 AM (I'm getting old and have to get up), and the network shows that I'm uploading something at full speed, even though my computer is supposedly sleeping.

It isn't a back-up program that I'm running.

I would encourage COLA readers and OSS advocates to explore this in more detail.

get someone with Office 2007 to send you a docx file. unzip it using pkzip or winzip or unzip.

look at the binary files.

replace one binary object with another.

zip up the document,

see if your office-2007 user can read the "enhanced" document.

For those of you with OLE programming skills, create an OLE object that creates a file, and e-mails that file to you using smtp.

Send a document with this new ole object embedded (along with the others) and see if you get an e-mail.

I haven't tried this, and I don't know if it will work. I'm not sure how hard it would be to make it work. I just think it might be an interesting project worth investigating, especially if you are considering the migration of a few thousand users to Vista and Office 2007.

I'd love to see what the results turn out to be. After all, if it's that easy to take control of a recipient's machine just by sending them a "trusted" Word, Excel, or PowerPoint attachment, just think how much chaos a really aggressive malicious hacker, with a goal of obtaining marketable information about your business, could do.




Does ISO really want to approve such a 'virus'? As an international standard even? If someone tests the above, please post the outcome here or elsewhere. It would prove invaluable.

The last time a chain of ISO problems was cited, Ian Easson challenged an argument from Groklaw. He might wish read the following lengthy follow-up. ISO is in a deeper puddle of mud than before.

Brazil is a P member of SC 34, so according to my reading of the clause, it has the right to appeal if any of the three above issues apply, and arguably they all do. According to South Africa, if the issue is ISO's reputation, or if there is a matter of principle involved, Brazil can appeal. Even point three could apply, in that Brazil raises matters such as incorrect tabulation of votes, which, if true, one would hope ISO wasn't aware of.

[...]

Why did they bother to go, one might ask? Why vote, if votes disappear from the record? By my reading, Brazil paints a picture of an orchestrated event, tilted away from criticism or a negative result and a refusal to give substantive consideration to issues delegates wanted to discuss, due to time constraints Brazil calls arbitrary, and worse.


For details about the BRM in question, see [1, 2, 3, 4, 5, 6, 7, 8] and have your jaw sink to the floor. It was a bad plan from the get-go [1, 2, 3, 4, 5], but Emperor Microsoft was in a hurry and it even used its lobbyist Jan Van Den Beld to change the rules 'on the fly'.

OOXML protests in India
From the Campaign for Document Freedom

Recent Techrights' Posts

Mainstream Media is Paid to Link "AI" Criticism/Boosting to Jeffrey Epstein Enablers, in Effect Showing How Corrupt This Media Became
Many readers will have noticed what was a paid-for PR campaign of a global scale
GNU/Linux Does Not Need Social Control Media to Succeed
When it comes to Social Control Media, Richard Stallman was right
SLAPP Censorship - Part 163 Out of 200: Attack on Computer Science and on Computer Security (or Associating Back Doors and Kill Switches With "Security")
Nowadays there are many who pretend to be security professionals
 
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, August 27, 2026
IRC logs for Thursday, August 27, 2026
After Many Waves of PIPs (Silent Layoffs) IBM Makes Non-Silent Layoffs, Effective Next Week (September)
What we heard is turning out to be true
Gemini Links 27/08/2026: Oklahoma, Tennessee, Haiku OS, Digital Resistance, and Staying Offline
Links for the day
Links 27/08/2026: Facebook to Pay Up to $17.1 Billion to Cover Up Known Harms, Nepal Landslide Kills Many
Links for the day
The Register MS Has Just Published Paid Spam That Says "AI" 19 Times
1.5 hours ago
RSS is King: Why Having Subscribers or Followers in Sites You Neither Own Nor Control is Loss of Autonomy and Search is Mostly Slop (Plagiarising Sites, Not Linking to Them)
Because digital connections in third parties aren't assets; they endow another party with tremendous power over people (e.g. MElon getting to decide who can and cannot reach people or what messages to "dim down")
Claims of Tens of Thousands of 'Silent Layoffs' at IBM (and Red Hat)
Looking at recent activity in thelayoff.com, about 80% of the comments and posts are about PIPs
Links 27/08/2026: "Flock’s CEO Is Lying to Cops" and Microsoft's GitHub Actions Breaks Down Again (Too Many Layoffs, Loss of Knowledge)
Links for the day
Clownflare Sees GNU/Linux and ChromeOS at Over 13% in Bahamas
Narrowing down to desktops and laptops, and judging by Web requests that go through Clownflare, many people there use GNU/Linux or Google's 'bastardised' version of it (with spyware preloaded)
Richard Stallman Complains That Linux Gives a Bad Name to GNU and Asks for Feedback on What's Wrong with Systemd (and Wayland)
Maybe some people want to send him a detailed, polite explanation
Increasing Focus on Patent Injustices
We'll soon cover the EPO a lot more
There's No "Next XBox"
Nothing comes ahead except layoffs and price hikes
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, August 26, 2026
IRC logs for Wednesday, August 26, 2026
Gemini Links 27/08/2026: Conditioning, Lagrange 1.21, and Computer Games
Links for the day
Links 26/08/2026: Patent Troll InterDigital Utilises Software Patents in Unconstitutional Court, "WikiHow Launches Copyright Infringement Suit Against" LLM Plagiarism
Links for the day
The Register MS Has New Fake Article ("SPONSORED FEATURE") With "AI" 21 Times In It
The Register MS is one among many culprits
Gemini Links 26/08/2026: “Doomsday Clock”, Rwanda Genocide, and Boasting About Using LLMs Instead of Writing Code (Due to Employer's Pressure)
Links for the day
No Allure in Omarchy, the Political Hyenas Only Give it More Free Publicity
To me, Omarchy seems like a weak project because of the slop (an HR problem)
Twitter is Not an API or a Communication Site, It's a Really Bad Site That Forces You to be Enslaved by Its Algorithm (Amplifying Its Owner's Worldviews)
the crackdown on Nitter means we should all avoid accessing or linking to x.com (Twitter)
Don't Let Bastards and Haters Grind You Down
They say "jealousy is the sincerest form of flattery"
GNU/Linux Rose in Caribbean Islands
combined population is measured at 44,182,048
IBM's Quantum Computing Lies Explained Again by Sabine Hossenfelder
To become a CEO at IBM one must lie
Controlling Culture and Social Behaviour by Digital Locks
if you don't fully control the technology in your possession, then you're not using that technology, this technology covertly uses you
Goodbye, Dolly
This week we say "goodbye, Dolly."
Links 26/08/2026: Election Bribery (aka Vote-Buying) Deemed "OK" in the US, "Nitter is Shutting Down After a Cease and Desist Letter" by MElon
Links for the day
Analogue So Much Better and Faster
From what we can gather, the tram ticketing system does not use Windows; we never saw it crashing or rebooting (or showing some Windows logo) in decades, so we assume it runs some kind of Linux
Linux Today Dumped All Social Control Media Last December
Linux Today seems to have concluded that all Social Control Media is just a waste of time
Don't Say X.com is OK Because People Can Access It by Alternative Means
Can Mozilla please clarify who inside Mozilla greenlit a return to X.com?
The Reach of techrights.org Is Increasing
We are on the side of women victims
SLAPP Censorship - Part 162 Out of 200: An Outline of Events
An outline of events
Pushed to Live
We still have some other work - stuff related to the editing of pages - which is work in progress and has been subjected to testing for many months
GNU/Linux Measured at 10% in Germany, Based on Cloudflare
It's peaking late at night
Richard Stallman's GNU Project Began 42 Years Ago With GNU Emacs and More
GNU Project announced almost 43 years ago (next month it's the anniversary)
Fake Articles "Sponsored by HPE" Published in The Register MS
Selling proprietary products as 'alternatives' to other proprietary products
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, August 25, 2026
IRC logs for Tuesday, August 25, 2026
Gemini Links 26/08/2026: Journal Plans and Extending Finger Protocol
Links for the day