a tool to create undetectable malicious Microsoft Office documents / Boing Boing



[ad_1]

Evil Clippy comes from Dutch Outflank security researchers: "A tool that helps red test teams and security testers create malicious MS Office documents, including Evil Clippy that can hide VBA macros, hide VBA code (via p-code) and scramble common macro scans It runs on Linux, OSX and Windows ". The magic of Evil Clippy depends in part on some terribly terrible and undocumented features of the Office, including "VBA Stomping": "If we know the MS Office version of a target system (eg, Office 2016 , 32 bits), we can replace our malicious VBA source code with fake code, the malicious code will always be executed via P code. Meanwhile, any tool analyzing the source code of VBA (such as an antivirus ) is completely fooled. "(via Eva)

<! –

Cory Doctorow

I write books. My latest are: A graphic novel by YA titled In Real Life (with Jen Wang); a documentary book on the arts and the Internet titled Information Does not Want to Be Free: Laws for the Internet Age (with introductions by Neil Gaiman and Amanda Palmer) and a science fiction novel YA titled Homeland (continuation of Little Brother). I speak everywhere and I tweet and tumble too.

->

[ad_2]

Source link