Microsoft to block internet macros by default in five Office applications

Discussion in 'other software & services' started by ronjor, Feb 7, 2022.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    179,066
    Location:
    Texas
    Catalin Cimpanu February 7, 2022
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Why haven't they done this before? Also, shouldn't the firewall play a big role into blocking these kind of attacks? After all, if processes, system based or not, can't communicate with the internet, I assume they can't download and execute the malware.
     
  3. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,190
    Location:
    USA
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,546
    Location:
    U.S.A. (South)
    M$ macros for Office but won't protect users? Why should we not be surprised.
     
  6. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,190
    Location:
    USA
    As the saying goes, Every change breaks someone's workflow. Someone is always going to be unhappy regardless of what you do.
     
  7. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Acc. to this BC article, the decision by Microsoft to not block macros is a temporary one?

    Here is a guide I see that you can use to restore the blocking capability.

    https://www.bleepingcomputer.com/ne...s-in-microsoft-office-docs-from-the-internet/

    Andy Ful has also released a new version of Hard_Configurator. :thumb:

    https://malwaretips.com/threads/har...ening-configurator.66416/page-189#post-996137
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Yes correct, some companies complained about this. But I wanted to make a joke about that malware is now blocked too easily, and this was bad for MS Defender sales LOL. :D
     
  9. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Wow, not only was this temporary, it was extremely temporary (by Microsoft standards).

    https://www.bleepingcomputer.com/ne...blocking-office-macros-by-default-once-again/

     
  10. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,314
    strange decision, either this or that. any file from the web has an ADS which informs about the zone. internet is an untrusted zone by default. Allowing untrusted files with activated macros is seriously stupid from my view. macros are disabled by default on our work computers, activating - also editing - must explicit being allowed.

    lol
     
  11. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,190
    Location:
    USA
    It was way shorted than I expected.
     
  12. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,190
    Location:
    USA
    Hex editing Microsoft files just seems like a really bad idea.
     
  13. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "As Microsoft blocks Office macros, hackers find new attack vectors

    Hackers who normally distributed malware via phishing attachments with malicious macros gradually changed tactics after Microsoft Office began blocking them by default, switching to new file types such as ISO, RAR, and Windows Shortcut (LNK) attachments...

    In a new report by Proofpoint, researchers looked at malicious campaign stats between October 2021 and June 2022 and identified a clear shift to other methods of payload distribution, recording a decrease of 66% in the use of macros.

    At the same time, the use of container files such as ISOs, ZIPs, and RARs has grown steadily, rising by almost 175%..."

    https://www.bleepingcomputer.com/ne...ffice-macros-hackers-find-new-attack-vectors/
     
  14. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  15. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,314
    i meant regular editing, files are read only on opening. Word shows a yellow message line for this and that.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.