<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; word-vulnerability</title>
	<atom:link href="http://www.darknet.org.uk/tag/word-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Word 0-day Exploits &#8211; QUESTION.DOC</title>
		<link>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/</link>
		<comments>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/#comments</comments>
		<pubDate>Thu, 11 Jan 2007 05:30:39 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-word]]></category>
		<category><![CDATA[microsoft-exploit]]></category>
		<category><![CDATA[microsoft-hacking]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[word]]></category>
		<category><![CDATA[word-vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/</guid>
		<description><![CDATA[There&#8217;s been quite a few Microsoft related exploits recently, but not in Windows, people have moved their focus towards the application layer and the top of the OSI stack. This time it was a 0-day Vulnerability in Microsoft Word. The original news comes from SANS Internet Storm Center Diary (ISC). Microsoft has reported Word 2003, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There&#8217;s been quite a few Microsoft related exploits recently, but not in Windows, people have moved their focus towards the application layer and the top of the OSI stack.</p>
<p>This time it was a 0-day Vulnerability in Microsoft Word.</p>
<p>The original news comes from <a href="http://isc.sans.org/diary.html?storyid=1925">SANS Internet Storm Center Diary (ISC)</a>.</p>
<p>Microsoft has reported Word 2003, Word 2002, Word 2000 and Word Viewer 2003 are reportedly affected.</p>
<p>The vulnerability is being exploited in the wild, the malicious document is called <em>QUESTION.DOC</em>.</p>
<p>Password stealing Trojan spreads with this vulnerability, link to the McAfee <a href="http://vil.nai.com/vil/content/v_141057.htm">PWS-Agent.g</a> writeup.</p>
<p></p>
<p>US-CERT reported today that &#8220;Word fails to properly handle malformed data structures allowing memory corruption to occur&#8221;. This vulnerability is public <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456">CVE-2006-6456</a> now.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D413+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;t=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/&amp;title=Microsoft+Word+0-day+Exploits+%E2%80%93+QUESTION.DOC" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F01%2Fmicrosoft-word-0-day-exploits-questiondoc%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/01/microsoft-word-0-day-exploits-questiondoc/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trojan for the Word Vulnerability in the Wild</title>
		<link>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/#comments</comments>
		<pubDate>Tue, 23 May 2006 03:59:13 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[microsoft-word]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[word-exploit]]></category>
		<category><![CDATA[word-vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/</guid>
		<description><![CDATA[We all knew it was just a matter of time until the &#8216;thing&#8217; was out. PandaLabs has detected the appearance of 1Table.A, a malicious code that exploits a recently detected critical vulnerability in Microsoft Word, and which also affects versions of MS Office 2003 and XP. Microsoft confirmed today the existence of this vulnerability and [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>We all knew it was just a matter of time until the &#8216;thing&#8217; was out. </p>
<blockquote><p>PandaLabs has detected the appearance of 1Table.A, a malicious code that exploits a recently detected critical vulnerability in Microsoft Word, and which also affects versions of MS Office 2003 and XP.</p></blockquote>
<p>Microsoft <a href="http://www.msfn.org/comments.php?shownews=17204">confirmed</a> today the existence of this vulnerability and apparently is <a href="http://www.scmagazine.com/uk/news/index.cfm?fuseaction=XCK.News.Article&amp;nNewsID=560353">working</a> on a hotfix. </p>
<blockquote><p>This security problem allows the execution of code on affected systems and, more dangerously, allows the construction of malicious code which is indistinguishable at first glance from a normal Word file.</p></blockquote>
<p>That&#8217;s more than enough to get 70%* of the people who use Microsoft Office to download and execute the file. If they open .BAT, .COM and .EXE, opening a .DOC is everyday work.</p>
<p>This attack is not limited to .DOC files, still, they will be the most used extension. It can take place with a .XLS file with an embedded Word document.</p>
<p>1Table.A &#8211; the new trojan &#8211; is detected by most of the antivirus software, however, user&#8217;s should have they&#8217;r eyes open until patch is released by Microsoft <em>(even if they <a href="http://blogs.technet.com/msrc/archive/2006/05/20/429612.aspx">don&#8217;t consider it critical</a>)</em></p>
<p><strong>Source:</strong> <a href="http://www.net-security.org/virus_news.php?id=639">NHS</a></p>
<p><em>* 80% of the statistics are made on the spot!</em></p>
<p></p>
<p><a href="http://digg.com/security/Trojan_for_Word_Exploit_IN_THE_WILD_">Digg This Article</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Trojan+for+the+Word+Vulnerability+in+the+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D207+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;t=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/&amp;title=Trojan+for+the+Word+Vulnerability+in+the+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Ftrojan-for-the-word-vulnerability-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/trojan-for-the-word-vulnerability-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

