ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Tell us who is your IT Community Hero

RSS

Security News

OpenOffice password crack is open to abuse

Tom Espiner ZDNet.co.uk

Published: 23 Apr 2007 17:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have warned that password recovery tools for OpenOffice, the open-source application suite, are vulnerable to abuse.

The release of version 1.0.4 of Intelore's OpenOffice Password Recovery software on Thursday allows IT managers and systems administrators to recover OpenOffice passwords and discard formatting and editing restrictions — for example, locked cell protection and permissions. The software allows password recovery through brute force and dictionary-based attacks, or a combination of both.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

"Even if you have lost passwords for all your OpenOffice programs and documents, Intelore's solution can help you quicker than any similar program – OpenOffice Password Recovery supports simultaneous processing of several recovery projects with different attack profiles," said Dmitry Rozenbaum, chief executive officer of Intelore.

Although password recovery tools for Microsoft applications have been available for at least six years, OpenOffice Password Recovery is one of the first commercially available tools for open-source products. But security experts have warned that such tools could be open to abuse.

"These kinds of tools can be used for both good and bad," said Graham Cluley, senior technology consultant for security vendor Sophos. "It's a grey area in software. Cottage industries for such tools are mushrooming. These applications can help people, but in the wrong hands they're a bit of a security concern." Cluley added that IT managers could set policies about who could have access to such tools on a business network.

Paul Wood, senior analyst at email security vendor MessageLabs, said that it opened a possible attack vector from disgruntled employees. "One attack vector is if a rogue employee has access to file-share password-protected documents. They can copy them, take them offline, and brute-force them at their leisure." Wood added that companies should lock down privileges, and consider encryption for sensitive documents.

OpenOffice Password Recovery version 1.0.4 is available to download for evaluation. The full business version costs $129 (£65). The product offers Unicode support and allows for recovery of multi-language passwords. OpenOffice Password Recovery version 1.0.4 can also recover a password containing typing errors, according to Interlore.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
18 out of 27 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

SAN Administrator - Mainframe - Storage - IBM DS8100 - ESS

The role is to maintain and manage all aspects of the SAN environment, including DR, data management and backup & recovery across multiple platforms. ...

Apache Webmaster (Apache, CEDAR, Business Objects) 6-Month Contract

My Glasgow based client is looking for an Apache Webmaster (Apache, CEDAR, & Business Objects) for a 6-Month contract, You will be required to ...

Exchange Administrator

Work involves the day to day maintenance and configuration of the Exchange environment, management of the DNS servers, session logs, the management ...