10/23/2008
Excel files becoming even more dangerous, see this
"In stead of creating and loading a temporary DLL from VBScript, I inject and execute shellcode directly from the VBA application. Some HIPS would prevent my previous script from running, because it loaded an unapproved DLL. But my new version doesn’t load a DLL." Didier Stevens a belgian security blogger developed this proof of concept.
What does it mean ? That a HIPS leaves too much passing by. This method should be tested with other code injection defenses. It shows again that downloads should be done in a sandbox on the machine.
15:22 | Permalink | Comments (0) | Email this
|
|
del.icio.us
|
|
Digg |
Facebook




Post a comment