All the latest UK technology news, reviews and analysis

Trojans a-Goga in Microsoft Word

by James Middleton

15 Jun 2001

Be the first to comment

  • Tweet this

A Trojan horse posing as a rich text Word document is exploiting a Microsoft Word flaw that was discovered over a month ago.

Anti-virus experts have warned that the Goga Trojan is capable of sending out user information, such as logins and passwords, from an infected machine.

The virus appears as a Rich Text Format (RTF) Word document which, when opened, exploits a flaw in Word's security.

The rich text document contains a link to a Russian website, which features a malicious macro code that executes a small utility in the RTF file's binary section.

This utility searches the computer and dumps internet access information into a text file which the macro script publishes into a publicly accessible guest book on the website.

The virus author, or anybody for that matter, can then browse the guest book to access the stolen information.

Kaspersky Labs said the best form of defence against this virus is to download the Microsoft Word patch available here, which closes the security gap that allows the macro to work.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Web Development Manager / Team Leader / PHP / MySQL

Development Manager / PHP Developer / MySQL / LAMP...

Process Expert for Information/Content Management

Process Expert for Information/Content Management...

SSIS Developer / Implementation Specialist

SQL Server / SSIS / ETL / T-SQL Data Migration A...

Linux Systems Administrator / Network Systems Admin

Linux Systems Administrator / Linux CentOS / Network...

To send to more than one email address, simply separate each address with a comma.