lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 3 Jan 2004 15:20:26 -0500
From: "Jerry Shenk" <jshenk@...ommunications.com>
To: <bugtraq@...urityfocus.com>
Subject: RE: Microsoft Word Protection Bypass


Their advisory says that this protection is only to protect against
accidental modification....harumph!  That's not what they used to say;)

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodt
echnol/office/office2000/reskit/ork2000/html/65t2_2.asp

-----Original Message-----
From: Thorsten Delbrouck-Konetzko
[mailto:Thorsten.Delbrouck@...rdeonic.com] 
Sent: Friday, January 02, 2004 5:51 AM
To: bugtraq@...urityfocus.com
Cc: Microsoft Security Response Center
Subject: Microsoft Word Protection Bypass


Hi all,

Microsoft Word provides an option to protect "forms" by password. This
is 
used to ensure that unauthorized users cannot manipulate the contents of

documents except within specially designed "form" areas. This feature is

also often used to protect documents which do not even have form areas 
(quotations/offers etc.).

This form protection can easily be removed without any additional tools 
(apart from a hex-editor).

Please find the full advisory attached.

best regards,
/tdk

-- 
 Thorsten Delbrouck
 Chief Information Officer

 Guardeonic Solutions AG
 Rosenheimer Str. 116
 D-81669 Munich
---------------------------------





Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ