10/23/2008

Excel files becoming even more dangerous, see this

"In stead of creating and loading a temporary DLL from VBScript, I inject and execute shellcode directly from the VBA application. Some HIPS would prevent my previous script from running, because it loaded an unapproved DLL. But my new version doesn’t load a DLL." Didier Stevens a belgian security blogger developed this proof of concept.

What does it mean ? That a HIPS leaves too much passing by. This method should be tested with other code injection defenses. It shows again that downloads should be done in a sandbox on the machine.

15:22 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment