Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
1–10 of 158 posts
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#2Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#3I can’t find a date for this paper, there is nothing on the web page or PDF
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#4I can’t find a date for this paper, there is nothing on the web page or PDF
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#5I can’t find a date for this paper, there is nothing on the web page or PDF
(Reference [12] is from Usenix July 2022. See "Prior work" in the introduction).
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#6I can’t find a date for this paper, there is nothing on the web page or PDF
It's a recent paper.
[1] https://casa.rub.de/en/research/publications/detail/every-si...
[2] https://www.usenix.org/system/files/sec23summer_235-rohlmann...
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#7Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#8Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#9I've heard the same for Windows code signing certs - that's it possible to modify the payload and have the signature still apply.
Re: Every Signature Is Broken: Insecurity of Microsoft Office’s Ooxml Signatures
#10I've heard the same for Windows code signing certs - that's it possible to modify the payload and have the signature still apply.
> These attributes are not part of the signedAttributes which is used to actually authenticate the signature
https://learn.microsoft.com/en-us/archive/blogs/ieinternals/...
> unverified data within the PKCS #7 blob itself which will not be taken into account when verifying the Authenticode signature