EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

07.12.08

Taking Microsoft OOXML to Task

Posted in ISO, Microsoft, Open XML, OpenDocument, Security at 2:13 pm by Roy Schestowitz

Any Windows/Office debuggers in the audience?

The following is a reproduction of a new post from Rex Ballard (I started this discussion thread), whose previous post we quoted the other day.


Message-ID: <31a66169-d9e7-4715-9e9e-e3488ebd36a9@25g2000hsx.googlegroups.com>
From: Rex Ballard <rex.ballard@gmail.com>
Newsgroups: comp.os.linux.advocacy
Subject: Re: Leaked ISO Document Reveals Crooked ISO Amid MS OOXML Corruptions
Date: Sat, 12 Jul 2008 08:20:23 -0700 (PDT)

[...]

ODF is a comprehensive document that provides detailed specifications
from the high level document content down to the smallest elements of
scalable vector graphics. There are some “standard” mime object types
that are supported, such as PNG and JPEG, but other embedded formats
must be installed using plug-ins which have to be authenticated by the
user and by the system at installation time, and cannot be installed
by the content. Furthermore, the installed content can easily be
identified as trustworthy or not, and can be restricted in it’s
capabilities.

OpenXML on the other hand, is a high-level specification which
describes the high level envelopes used to embed binary objects which
are included in the content. The content itself contains the binary
code which can call any function in any Microsoft library and has all
permissions of the person opening the document. If a user account is
set up as “Administrator”, then the application can mess with the
registry, create, download, and hide files, can execute applications
in those files, can install any number of new viruses, and generally
wreak havoc on the system.

I’ll leave it to others to document the exact details (as I said, I’m
busy these days), but I’m sure anyone who tries to publish these
vulnerabilites will probably find themselves getting the same
treatment that Tracy Reed of Ultraviolet.org got when he tried to
publish his warnings about ActiveX controls back in 1997. Microsoft
got a court injunction against him, and forced him to take down the
content, claiming that it was being used to encourage hacking, and was
damaging the Microsoft brand.

“I got a couple of docx documents and had trouble getting them to open, even with the plug-in for Office XP. Next thing I know, I get a notice from my registry auditor that I have 1300 new registry errors.”Over the last 10 years,
we’ve seen these very same
techniques, documented back in 1997,
used widely to spread viruses including
Melissa, Nimda, Sky, BugBear, and about
250,000 other viruses, worms,
and malware, not including spy-ware and
other “Microsoft Authorized”
invasions of our privacy.

I got a couple of docx documents and had trouble getting them to open,
even with the plug-in for Office XP. Next thing I know, I get a
notice from my registry auditor that I have 1300 new registry errors.
And suddenly, my PC is churning the disk-drive and the network
connection at 3:00 AM (I’m getting old and have to get up), and the
network shows that I’m uploading something at full speed, even though
my computer is supposedly sleeping.

It isn’t a back-up program that I’m running.

I would encourage COLA readers and OSS advocates to explore this in
more detail.

get someone with Office 2007 to send you a docx file.
unzip it using pkzip or winzip or unzip.

look at the binary files.

replace one binary object with another.

zip up the document,

see if your office-2007 user can read the “enhanced” document.

For those of you with OLE programming skills, create an OLE object
that creates a file, and e-mails that file to you using smtp.

Send a document with this new ole object embedded (along with the
others) and see if you get an e-mail.

I haven’t tried this, and I don’t know if it will work. I’m not sure
how hard it would be to make it work. I just think it might be an
interesting project worth investigating, especially if you are
considering the migration of a few thousand users to Vista and Office
2007.

I’d love to see what the results turn out to be. After all, if it’s
that easy to take control of a recipient’s machine just by sending
them a “trusted” Word, Excel, or PowerPoint attachment, just think how
much chaos a really aggressive malicious hacker, with a goal of
obtaining marketable information about your business, could do.


Does ISO really want to approve such a ‘virus’? As an international standard even? If someone tests the above, please post the outcome here or elsewhere. It would prove invaluable.

The last time a chain of ISO problems was cited, Ian Easson challenged an argument from Groklaw. He might wish read the following lengthy follow-up. ISO is in a deeper puddle of mud than before.

Brazil is a P member of SC 34, so according to my reading of the clause, it has the right to appeal if any of the three above issues apply, and arguably they all do. According to South Africa, if the issue is ISO’s reputation, or if there is a matter of principle involved, Brazil can appeal. Even point three could apply, in that Brazil raises matters such as incorrect tabulation of votes, which, if true, one would hope ISO wasn’t aware of.

[...]

Why did they bother to go, one might ask? Why vote, if votes disappear from the record? By my reading, Brazil paints a picture of an orchestrated event, tilted away from criticism or a negative result and a refusal to give substantive consideration to issues delegates wanted to discuss, due to time constraints Brazil calls arbitrary, and worse.

For details about the BRM in question, see [1, 2, 3, 4, 5, 6, 7, 8] and have your jaw sink to the floor. It was a bad plan from the get-go [1, 2, 3, 4, 5], but Emperor Microsoft was in a hurry and it even used its lobbyist Jan Van Den Beld to change the rules ‘on the fly’.

OOXML protests in India
From the Campaign for Document Freedom

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • StumbleUpon
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Propeller
  • Slashdot
  • Technorati
  • TwitThis
  • Webnews
  • YahooMyWeb

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channel. To use your own IRC client, join channel #boycottnovell in FreeNode.

Pages that cross-reference this one

What Else is New


  1. Eye on Microsoft: Signs of Game Over

    The press seems pessimistic about Microsoft, which is increasingly seen as unable to evolve and innovate; Microsoft's security problems (and security PR) persist in a major way



  2. Windows 'Battery Killer' (Vista 7) Also Has USB Data Transfer Issues and Stability Problems, Does Not Sell Well

    Vista 7 is plagued by serious bugs and new patches from Microsoft are said to be making things even worse; Microsoft is still unable to formulate a response to the new problems and Vista 7 sales continue to disappoint, so more vapourware and fake "leaks" are being used instead



  3. Norwegian Agency for Public Management and eGovernment Slams Microsoft OOXML

    The authorities in Norway justify the country's decision to reject Microsoft's standards-hostile ploy



  4. Steve Ballmer Visits Obama Once Again as His Fight Against Google Continues

    Updates on the competition between Microsoft and Google -- a rivalry that takes political form



  5. Microsoft's Hostile Takeover of the Healthcare System

    Microsoft wants to make medical records and management of patients a lot more dependent on Windows and its own private servers



  6. More Mono and Patent Poison from Novell

    “Pinta” comes from Novell staff and software patents tax (on SLE*) comes from Microsoft in the form of vouchers



  7. Patents Roundup: EFF Defends VoIP; Google, Apple, and Black Duck Stifle Progress; Microsoft Joins RPX

    A quick look at some patent news from the past week, ranging from defence to offence



  8. United Nations and World Bank Help Bill Gates and Microsoft Colonise Africa

    Microsoft's and Gates' incursions in Africa are backed by self-serving Western agenda of patents and proprietary software



  9. IRC: #boycottnovell @ FreeNode: February 8th, 2010

    IRC Log for February 8th, 2010



  10. Links 8/2/2010: Linux 2.6.33 RC7 and Parsix GNU/Linux 3.0r2 Released

    Links for the day



  11. Xbox 360 Still Under Many Lawsuits

    Lawsuits from many fronts add to the trouble that Microsoft's Xbox 360 already faces



  12. Facebook and Microsoft Revisited; New Examples of Microsoft Entryism

    A look at Facebook's relationship with Microsoft in 2010; Microsoft employees have an effect in competitors of Microsoft, so this issue is addressed too



  13. Microsoft Still Exploits the Taxpayers-Funded NASA to Spread Silver Lie and Close Down Research

    Microsoft-imposed corruption of NASA's obligation to the public carries on as it strives to capture academia too



  14. Microsoft 'Cloud' Falls Offline for a Quarter of a Day, Zune 'Cloud' Deletes Music, Microsoft Shop Also Kaput

    Microsoft continues to give online operations and online storage a bad name because of its sheer incompetence



  15. Ubuntu Perspectives: Signs of Change

    Analysis of Canonical's latest moves, which are being defended by some and severely criticised by others



  16. Apple's Newton Executive Negative About Apple's Latest Attempts at a Shinier Newton

    Apple's iPad still faces sometimes-overwhelming criticism, even from the company's own supporters and existing/former staff



  17. Microsoft Loses Another Vice President, Management Vacuum Alarms the Press

    Another Microsoft Vice President has just left Microsoft, joining the ranks of many more



  18. IRC: #boycottnovell @ FreeNode: February 7th, 2010

    IRC Log for February 7th, 2010



  19. Links 07/2/2010: Linux Mint 8 KDE, Linus on Nexus One

    Links for the day



  20. Patents Roundup: Extortion, Protection Rackets, Patent Trolling, and Small Victory for Mozilla

    Johnson and Johnson's multi-billion-dollar patent fine, patents' harms to real science and life, patent trolls thrive, and Mozilla's opposition to patent-encumbered codecs gradually pays off



  21. The Microsoft Apologists and Boosters Really, Really Like Novell!

    A complete list of news articles about Moonlight 3.0 preview shows that its biggest fans are Microsoft fans



  22. iPad is Like Zune

    iPad -- like Zune -- might not reach the European Union (EU), possibly due to lukewarm reception and lack of appeal, not trademarks



  23. Microsoft Shows Yet Again That It is Allergic to GNU/Linux

    Microsoft's hatred of GNU/Linux, as demonstrated in this weekend's news



  24. Michael Arrington a Hypocrite: Bribed by Microsoft Yet Fires Bribed Bloggers

    Another fine example of an influential blogger who sells out to Microsoft yet does not apply to himself the same standards that he applies to colleagues



  25. Microsoft Refuses to Comment About (Deny) the Sex Parties, Drug Use

    No denial from Microsoft in the face of very strong allegations



  26. Another Misdirected Response from the Government to the Company “Not Engineered for Security”

    Another terrible month for Microsoft insecurity and the government is still unable to respond sensibly to the threat



  27. IRC: #boycottnovell @ FreeNode: February 6th, 2010

    IRC Log for February 6th, 2010



  28. Links 6/2/2010: GNOME Journal Released, ARM CEO Sees Bright Future

    Links for the day



  29. Novell Executives Still Cannot Write Blog Posts?

    New evidence of ghostwriters in Novell's own Web site



  30. Microsoft Wants More Licensing Instead of Windows Bans

    At the World Economic Forum in Davos, Microsoft super-lobbyist Craig Mundie requests new laws that complicate the Internet and ignore the real problem (Microsoft negligence)


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts