MS Excel Users Susceptible To New Vulnerability
nandemoari writes "Microsoft has warned users that yet another critical vulnerability has been found in its popular Office spreadsheet program Excel. The flaw could allow remote hackers to open and run malicious code on an unsuspecting user's computer through an infected spreadsheet file.
Products affected include Office 2000, Office 2002, Office 2003, Office 2007, Office 2004 for Mac, Office 2008 for Mac, and the Open XML File Format Converter for Mac."
http://it.slashdot.org/article.pl?sid=09/02/24/1938259
I hadn't heard
No sig for you!!
... to create a vulnerability on my Mac.
I choose to use open office, even though I get M$ office free through work.
Lawyers, MBA's, RIAA? A jedi fears not these things!
a 0 day exploit?
Does this mean that OpenOffice is the workaround for the moment?
Pewwww, finally Microsoft comes to the rescue and takes the heat from us, as always. Bob, send the excel team a cake.
Second dupe today from nandemoari going to infopackets.com.
Someone's fishing for traffic here.
... is a reliable indicator of who sent the email... ;-)
Is this a flaw in the Operating System or a flaw in the application like the Adobe one and who is to blame this time ...
... is a reliable indicator of who sent the email... ;-)
Well, even if it appears to come from someone you know, it's not that difficult to avoid.
Here's a test. Would you open the attachment if you received the following email from your mom?
From: Mom
Subject: info
Attachment: morgage.xls
here is the info you reqeusted
"You cannot simultaneously prevent and prepare for war." -- Albert Einstein
http://support.microsoft.com/kb/935865
They have the code to do this securely... but can't implement it because users want the features which allow security holes. Disable macros and probably internet connections too, convert the file, then open it. Look at all the "issues", which are essentially MS saying these are dangerous (but still in the design).
"Our own research, however, has concluded that open source software exposes users to significant and unnecessary business risk, as the security is often overlooked, making users more vulnerable to security breaches,"
"That's not to say that commercial software isn't without risks, but any flaws on commercial applications tend to get patched a lot faster than on open source, as the vendors producing the software have a lot more to lose than an open source programmer,"
"New variant of Conficker worm circulates"
Yes, because I know how bad my mum is at spelling - the misspelling of mortgage is a dead give away that it's her.
http://it.slashdot.org/article.pl?sid=09/02/25/024211
Yet another case where a document has blurred into an application, the way Windows blurred from a WM to an OS.
DONT CROSS THE STREAMS! Curse you von Neumann.
I want to delete my account but Slashdot doesn't allow it.
So why does Secunia have 861 OSX vulnerabilities listed? And if "pretty much" all the problems have been external why does Apple release patches so frequently? Do they patch other peoples code?
You must not know very many people. I have gotten many valid messages of that caliber of spelling and grammar. Hell, I'm lucky if they even have a subject sometimes.
My blog. Good stuff (when I remember to update it). Read it.
As with any religion those facts are swept under the table to better keep the faith. Only think happy thoughts, don't let reality distract the warm fuzzy feelings...
Oo Writer is fine, and I use Oo exclusively at home on the principle that document standards should be open.
But yes, I use Excel at work and Calc at home, and Calc is very annoying by comparison.
For one thing, Excel will let you set a default number format (currency, integer, date, etc) on a whole row or column and whatever you enter thereafter will use that format. I try that with Calc, and it never works. Not only does it not remember the setting, but it forces me to apply the formatting to EACH individual cell AFTER entering the info.
And all I'm doing is keeping a simple balance sheet.
I work with security and would love to know how to craft such files for, *cough*, academic reasons. Any hints?
I wonder what the world would be like, if the law forced every software manufacturer to notify their users about known vulnerabilities - how severe they are and how long they have been unfixed... maybe have a widget on the desktop, showing the top 20 very severe, unfixed vulnerabilities... I think I would bet my life, that windows would hardly exist on the market anymore...
The MAFIAA is a bunch of mindless jerks who will be the first up against the wall when the revolution comes