Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> you can disguise any exe as a rich text word doc that then faithfully re-expands the exe onto users runtime when the open the word doc

...and click through the warning.



If they are worried enough (that their boss has sent them a report to be checked by 4:30 or else) to open a doc in a mail, then they are worried / dumb enough to click through the warning (NB I comtract in Fortune 500 and every time I open my own excel file on my own desktop I have to click through three yes/no. It's no longer a defence)


Yea, I was waiting to see the "and to disable the warning" part of the tutorial. But to be fair, even though you or I would be stopped by the warning, most people wouldn't.

Really OLE needs to be deprecated and removed. It's ancient cruddy technology. It needs to die like ActiveX and <IE11


Like ActiveX? A Microsoft ActiveX control is essentially a simple OLE object that supports the IUnknown interface.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: