mailing list archives
Remote file inclusion by office applications
From: Timo Warns <Warns () Pre-Sense DE>
Date: Thu, 13 Dec 2012 15:59:13 +0100
I would like to hear some opinions on whether remote file inclusion by
office applications should be considered as security-relevant.
Different office applications automatically include remote files on
opening local files. Examples include MS Word  and
I can imagine different impacts:
- The origin of a document can track when a document has been opened and
possibly by whom.
- The origin of a document can arbitrarily change the displayed content
of the document whenever the document is opened (without affecting hash
sums of the document). For example, the origin may change the content
of a remote image depending on from which IP or when the image is
accessed. For example, a sent tender may be changed after the tender
- Under certain conditions, remote content is directly embedded into
a document. This may allow to extract confidential data. For example,
LibreOffice/OpenOffice directly embed remote content when converting
a document into the PDF format. An attacker may send a document
referencing confidential data to a victim asking the victim to convert
the file. If the victim converts and sends the document back, the
attacker receives the confidential data.
In my opinion, these issues are a question of user expectation. Users
are aware that web browsers may access remote content even when opening
local files. I don't think users are aware that office application may
do the same. An 'offline mode' for office applications that is enabled
by default could meet user expectations.
- Remote file inclusion by office applications Timo Warns (Dec 13)