PSA: Don’t Open Random PowerPoint Presentations from Strangers
techcrunch.com
techcrunch.com
People are surprised and think it's strange when I request they send me files in .txt instead of .doc(x), .csv instead of .xls(x), .pdf instead of .ppt(x), reject HTML emails, etc. Some of these people are the same ones who manage to somehow get infected with tons of malware, even when they're running an AV.
The best alternative to a .ppt(x) is .pdf, and even that has had its share of exploits in the official implementation.
Getting exploited through complex badly documented file formats with a large attack surface using software with unknown source code,
versus
Simple compact well documented formats with a small attack surface using a reader with inspectable source code.
(even better if said source is actually regularly inspected, of course :-p)
I'm even a tad nervous about opening things like unsolicited/unexpected PDF files from people that I know.
Disclosure and licensing of the format doesn't actually prevent any of the security issues, so I'm not sure that "proprietary" is meaningful here.
"Don't use software whose security profile you aren't confident in to open files" might be a better rule -- but then you could drop the "to open files" part off without any loss of validity.
The 1989 Morris Worm exploited the loading of a character string into a C buffer (by means of the gets function). The data format there is "line of text (which may only be yay long)".
I think the main point here is "don't forward me documents that can only be viewed with large, complicated, closed-source programs, if you did not write those documents". This is reasonable.
As consumers we basically trust these proprietary programs not to be malicious in and of themselves. Let's put it this way: if Microsoft wanted to do something bad to your Windows PC, they could do it in so many ways not involving the loading of a specially crafted Office document.
We also trust documents created in these programs by people that we trust. If my friend created a PPT he wants me to view, it probably doesn't contain an exploitable hole. (Probably: because there could be some virus that spreads from malicious documents to good documents via exploit code running inside the document application.)
Taking random PPT's, DOC's and XLS's from some unknown sources on the Internet and circulating them to people in your address list: totally bad, unacceptable.
There is no reason that some circulating joke has to be a Word file! Even if the author thinks it requires colorful fonts: use HTML, damn it.
They're also standardized and have a rather large installed base, much of which is inconsistently updated. As attack surfaces go, they're large.
Relying on specific misfeatures to be present, exploitable, and useful on a diverse set of platforms is more chancy for the attacker.
'dragonwriter is exactly right: the provenance of the format has nothing to do with its security. What matters is its complexity, and even that is just a threshold matter --- past a certain (very common) point you're just screwed no matter what.
Default UAC option in Windows 7 and later is "Notify me only when applications try to make changes to my computer". That option is problematic because of various ways to exploit built-in apps to bypass UAC. "Always notify" is slightly less convenient but much more secure option.
(The last Microsoft Office product I bought was Word 97. The free stuff has been good enough for years now.)
you can get code to execute in all sorts of presumably innocuous file types.
If opening PowerPoint file throws up UAC promt, that is so good evidence for that file to not be legit that your prior estimation for it to be legit realistically can not be close enough to 100% to override this evidence.
So, if opening PowerPoint file or other office document throws up UAC promt:
1. Say No.
2. Warn person who send you that file and other people who could receive it. If you created this file or if you opened it before and it did not throw UAC promt, that means that your system is probably infected and may be all your other documents are infected, warn other people about it.
3. Send this file to VirusTotal.
4. Run antimalware check on your machine with free tool from legitimate antivirus vendor (such as Dr.Web CureIt, Kaspersky Virus Removal Tool, Microsoft Windows Malicious Software Removal Tool). If VirusTotal said you that some vendors already detect that file as malicious, use tool from one of such vendors you trust more. Otherwise, prefer vendor which is not vendor of your currently installed antivirus, then wait until VirusTotal will detect malware in your file, and repeat this step.
And how can HTML5 do anything that Excel can do?
2) HMTL5 can't do "anything Excel can do", which is why I didn't say it could. But a Google Drive spreadsheet can cover the needs of the great majority of people who need to publicly distribute spreadsheet documents.
There are definitely quantitative analyses that I would much rather do with Excel than with Google's HTML5 spreadsheet, but it's very uncommon to publicly distribute complex spreadsheets, and I'm talking about document interchange formats. The kind of spreadsheet you might embed on half of a page of a presentation is the kind of spreadsheet that HTML5 could easily handle.
The best tool out there right now is http://slid.es but it doesn't come close to letting you represent things visually.