Word Zero Day Mitigation

| | Comments (0) | TrackBacks (0)

I hear that a government agency (which I wont name) is blocking all email file attachments with a .doc extension as a result of the announced zero day attack. The email that I saw adviced employees to stick to TXT files and PDF files.

Every company has its own level of risk aversion but I think this is kind of ridiculous. Word documents are essential to business. I've asked before in this blog, you people with untrustworthy antivirus who block by file type what are you going to do when viruses come in flavors other than easily blockable things like EXE and PIF. Well, we found soon that viruses come in image files. Viruses come in office files. I guess the answer for this agency will eventually be to enforce text only email.

The Federal agency will be blocking .doc files until a fix is available or they feel the threat level has changed. I did hear that renaming the extension before mailing does circumvent this filter. So they aren't blocking using the file header, only by extension. If someone were truely targeting them specifically, and currently this attack is only used against one or two companies, the attacker might know enough to rename the file with instructions for the recipient to rename the .cod file back to .doc.

I'm a bit surprised that they are advising that PDF files are an acceptable alternative. Adobe Reader and Professional have all kinds of remote execution vulnerabilities. Adobe recommends that you upgrade to version 8 which was released this week.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Word Zero Day Mitigation.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/397

» "Security Conscious NASA" from Roger's Information Security Blog

MSNBC has an article on the Word doc banning at NASA that I alluded to earlier this week.... Read More

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on December 8, 2006 12:16 AM.

SANS Lunch and Learn with Stonewood Flagstone was the previous entry in this blog.

Should adobe release a 7.x patch for Reader/Professional? is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en