LWN.net Logo

[ooo-announce] proof-of-concept macro virus

[ooo-announce] proof-of-concept macro virus

Posted Jun 5, 2006 3:08 UTC (Mon) by AnswerGuy (guest, #1256)
Parent article: [ooo-announce] proof-of-concept macro virus

So, displaying a warning is good, but I have to wonder what other protections are in place.

I would think that the Macro feature should be limited (by default) to modifying/rendering the contents of the file in which it's embedded. There should be a special, trusted, directory in which "global" macros can be stored; and safeguards on how templates and macros get saved thereto.

The real dangers of macros in productivity application come from their ability to leak out of one document (receieved via e-mail or over any file sharing means) and read or modify other files (either to insert copies of, or links to, the macros --- for a viral/worm like behavior; or to corrupt them, even to steal sensitive data from them and send them back to some malicious 3rd party).

I'd like to see a more detailed, expert explanation of how OOo protects users from these sorts of things.

Jim


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds