Updated: 24.11.2002; 11:57:39 Uhr.
disLEXia
lies, laws, legal research, crime and the internet
        

Friday, February 16, 2001

Re: SiteGuest unauthorized address capture (Russell, RISKS-21.24)

http://www.privacyfoundation.org/advisories/advEmailWiretap.html gives an exploit that allows the spying ("wiretap") of written messages and used addresses when forwarding privately a received message with embedded code ...

Jean-Jacques Quisquater [Quisquater via risks-digest Volume 21, Issue 25]
0:00 # G!

The old ones are the best ones: Hidden info in MS Word documents

OK, this is an old one (dating back to 1994 according to the RISKS archive), but it was new to me when I came across it recently, and thought people might be interested in a couple of real life scenarios:

I received an MS Word document from a software start-up regarding one of their clients. Throughout the document the client was referred to as "X", so as not to disclose the name. However I do not own a copy of Word, and was reading it using Notepad of all things, and discovered at the end the name of the directory in which the document was stored -- and also the real name of the client!

I checked on a number of other word documents I had for hidden info, especially ones from Agencies who are looking to fill positions -- and yes, again I was able to tell who the client was from the hidden information in the documents.

Finally, I had a look at the Lockerbie Judgment document:

http://www.scotcourts.gov.uk/html/lockerbie.htm

Hoping to find something that would cause international uproar -- alas, no, just an ironic hidden message: "Are you surprised?". Yes, I was, actually -- I thought Ahmed Jibril did it.

Risks: What potentially damaging information is hidden in published documents in Word, PDF and other complex formats?

Mitigation: Use RTF when you can -- no hidden info, no viruses.

Paul Henry, emmo@hotmail.com ["Paul Henry" via risks-digest Volume 21, Issue 25]
0:00 # G!


Maximillian Dornseif, 2002.
 
February 2001
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28      
Jan   Mar

Search


Subsections of this WebLog


Subscribe to "disLEXia" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.