[Esa-l]IMPSEC works - or does it.

John D. Hardin jhardin at impsec.org
Fri May 18 06:43:12 PDT 2001

On Fri, 18 May 2001, Howard Lowndes wrote:

> I assume that php used file magic to determine what the file type
> was and was able to display the spreadsheet because it clearly did
> not use the file name extension and the MIME type was
> application/octet-stream.

Running on a *nix box, that's a safe assumption.

> What concerns me is whether any macros would have been executable
> had they been embedded.

Did it just render the spreadsheet, or did Excel actually get started
on the client's computer (perhaps embedded in their browser)? If the
latter, then yes, macros probably would get executed.

In this case there's little the sanitizer could do.

Does anybody know of a strip-VBA-from-MS-Office-Documents perl module?

