Twitter | Pretraživanje | |
Decalage
Final slides of my presentation yesterday at Black Hat Europe 2019, about malicious VBA macros and recent advances in the attack & defence sides: Featuring /olevba, ViperMonkey, MacroRaptor, EvilClippy
Reply Retweet Označi sa "sviđa mi se" More
Will Dormann 7. pro
Odgovor korisniku/ci @decalage2 @bry_campbell
Great stuff! I get that Microsoft can't just remove macro capabilities. However, given any enterprise network, I have to question what percent of workstations *need* macros to be enabled, operationally.
Reply Retweet Označi sa "sviđa mi se"
Will Dormann 7. pro
Odgovor korisniku/ci @decalage2 @bry_campbell
If it's a small number, then I suspect that macros disabled by default (and I mean actually disabled, not that silly "Enable Content" button that anybody can click) might go a long way in protecting people. I'm not an real sysadmin, so perhaps there are factors I'm not aware of?
Reply Retweet Označi sa "sviđa mi se"
David Ledbetter 5. pro
Odgovor korisniku/ci @decalage2
Wow, lots of good info packed into this pdf. Will this presentation be available to watch later ?
Reply Retweet Označi sa "sviđa mi se"
Decalage 5. pro
Odgovor korisniku/ci @Ledtech3
I think so, but it will take time before public release of all the Blackhat videos.
Reply Retweet Označi sa "sviđa mi se"
joël 14. sij
Odgovor korisniku/ci @decalage2
great presentation and research! Did you extract / analyse the SRP streams for the documents as well and made an attempt to classify the attachment?
Reply Retweet Označi sa "sviđa mi se"
Decalage 14. sij
Odgovor korisniku/ci @joelgun
Thanks 🙂 My tools do not parse SRP streams, I don't think their format is documented. Do you know any good reference about that? And what do you mean by "classify the attachment"?
Reply Retweet Označi sa "sviđa mi se"
Vess 5. pro
Odgovor korisniku/ci @decalage2
Regarding the idea to split VBA functions into safe and unsafe - Office did have something like this once. There used to be programs for viewing (but not editing) Office documents - WordView, etc. They could run only macros that didn't modify the environment.
Reply Retweet Označi sa "sviđa mi se"
Decalage 5. pro
Odgovor korisniku/ci @VessOnSecurity
Interesting, I thought those viewers didn't have a VBA engine at all.
Reply Retweet Označi sa "sviđa mi se"