[ooo-announce] proof-of-concept macro virus
Posted Jun 5, 2006 3:08 UTC (Mon) by
AnswerGuy (guest, #1256)
Parent article:
[ooo-announce] proof-of-concept macro virus
So, displaying a warning is good, but I have to wonder what other protections are in place.
I would think that the Macro feature should be limited (by default) to modifying/rendering the contents of the file in which it's embedded. There should be a special, trusted, directory in which "global" macros can be stored; and safeguards on how templates and macros get saved thereto.
The real dangers of macros in productivity application come from their ability to leak out of one document (receieved via e-mail or over any file sharing means) and read or modify other files (either to insert copies of, or links to, the macros --- for a viral/worm like behavior; or to corrupt them, even to steal sensitive data from them and send them back to some malicious 3rd party).
I'd like to see a more detailed, expert explanation of how OOo protects users from these sorts of things.
Jim
(
Log in to post comments)