ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Word flaw opens door to Trojan horse

Robert Lemos, ZDNet.com ZDNet US

Published: 15 Jun 2001 08:31 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A month-old flaw in Microsoft Word has opened up PCs to attack by a new Trojan horse, antivirus researchers said on Thursday.

Dubbed "Goga," the malicious code poses as a Word document saved in rich text format but actually reaches through the Net to run a Word macro -- a small program that runs within the application -- saved on a Russian Web site.

"While this is not a danger to the general public, it could be a danger to somebody if there is a direct mailing to them," said Jimmy Kuo, a researcher at security software maker Network Associates.

The Trojan horse appears as text file in the rich text format, or RTF, attached to an e-mail, according to British antivirus software company Kaspersky Labs, which first found the malicious program.

When opened, the RTF file will link back to a Word template file on a Russian Web site. The file contains a macro, which will steal and upload information regarding the victim's log-in and password to the guest book of a second site. An investigation of that site found only one record of any information, indicating the Trojan horse is not widespread.

By using a macro saved in a template hosted on another computer, the Trojan horse is able to fool Windows into letting the macro run, rather than flagging it as potentially dangerous code.

Outlined in a Microsoft advisory a month ago, the technique bypasses normal Windows security against such malicious programs.

"Normally, you could hit someone very easily only if their security settings were low," Kuo said. "By using this technique, you can bypass the security level."

Kuo stressed that Goga doesn't appear to be a worm or a virus, as it doesn't spread from computer to computer. He added, however, that the code does show that consumers can't trust attachments.

"There is no safe way to assume what" an e-mail attachment really is, he said.

Is your PC safe? Find out in ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
25 out of 68 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Discussions

1000030281 1000030281

Facebook Bans Firefox 3

Sunday 20 July 2008, 2:33 AM

1 comment
roger andre roger andre

SP3 Under Suspicion Again

Saturday 19 July 2008, 9:29 PM

2 comments

Blog Posts

Avatar roger andre

Facebook Bans Firefox 3

Saturday 19 July 2008, 7:54 PM

1 comment
Avatar geek

Windows Vista

Friday 18 July 2008, 7:58 PM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme