Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: Data hidden in Word documents
.

  • To: "Rohrer, Mark E" <[EMAIL PROTECTED]>
  • Subject: Re: Data hidden in Word documents
  • From: Ansgar Wiechers <[EMAIL PROTECTED]>
  • Date: Sun, 31 Aug 2003 13:52:07 +0200
  • Cc: [EMAIL PROTECTED]
  • In-reply-to: <[EMAIL PROTECTED]>; from [EMAIL PROTECTED] on Fri, Aug 29, 2003 at 07:15:15AM -0700
  • References: <[EMAIL PROTECTED]> <[EMAIL PROTECTED]>
.
 
On 2003-08-29 Rohrer, Mark E wrote:
> May not undo across saves, but using a simple hex-editor one can
> certainly see that the deleted text is still resident within the file,
> if not the document proper, unless specific actions are taken to
> sanitize the document.

Been there, done that. And no, the deleted text is not contained within
the document if you don't have quick-save and/or change-tracking
enabled.

I agree that the former is a real problem, since information may be kept
within a document when one would not necessarily expect it. The problem
with the latter is "just" the users not being aware of a feature doing
what it is supposed to do (keeping track of changes being made to the
document and allowing to view that changes). Anyway, both of them don't
have anything to do with how Undo works (which is the assertion I was
objecting to).

Regards
Ansgar Wiechers

-----------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.