Infosecurity Europe 2007
Infosecurity Europe 2007

Experts warn of .doc attacks

Legacy copies of Word wide open

Iain Thomson at Infosecurity Europe 2007

Security experts at Infosecurity Europe 2007 are warning of hack attacks and data theft being made easier by the use of hidden executables and a high-tech variant on the microdot spying technique.

The first attack involves planting an executable malware file in a Word document. When the document is opened it crashes the system and the malware is automatically loaded when the computer reboots.

Advertisement

"It is a cunning technique because antivirus software does not detect this kind of attack," said Pete Simpson, Threatlab active manager at Clearswift.

"A lot of legacy Word code is ripe for this kind of attack. It is the attack vector of choice for hostile intelligence agencies and professional criminals."

The second technique is a variant of the traditional spying method of microdotting, where information is photographed and reduced to the size of a dot and pasted into a document.

The new technique is similar, but uses text boxes in Word documents. Sensitive information can be pasted into a text box and then the box is reduced and placed in the document to resemble a punctuation mark.

But antivirus vendors are sure that existing security systems would stop the first kind of attack.

"It is a really nasty one to beat, but in the end it would fail if systems are up to date," said David Emm, technology consultant at Kaspersky Labs.

"Once the malware tries to run it would be picked up by its signature file, or by its actions being picked up by the heuristics engine."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft

New zero-day Word attack emerges

Attackers release exploit one day after Microsoft's monthly patch release

Microsoft

Third attack hits Microsoft Word

Three's company for text editor flaws

Trojan hits unpatched Microsoft Word flaw

Stealth attack targets specific corporations

Second Word zero day flaw found

Microsoft may have to rethink patch Tuesday

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

HTC Hero

Video: HTC Hero launch

Handset maker unveils its latest Android-based smartphone

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Twitter

Twitter charges are bad idea, say V3.co.uk readers

Over a third insist the service should remain free for...

great wall of china

Podcast Special: Views from the Valley

The hottest stories from the US, including news of China's...

Mobile phone charger

Top 10 articles, 3 July 09

Free upgrades for Windows 7, and standard mobile phone chargers...

Red Hat

Red Hat beta builds on virtualisation plans

Kernel-based Virtual Machine virtualisation added to latest Enterprise Linux beta

Primary Navigation