Microsoft, in accordance with its Open Specification Promise, has released the following file specifications to the public.
Word 97-2007 Binary File Format (.doc) Specification
PowerPoint 97-2007 Binary File Format (.ppt) Specification
Excel 97-2007 Binary File Format (.xls) Specification
Excel 2007 Binary File Format (.xlsb) Specification
Office Drawing 97-2007 Binary Format Specification
This is good news for open source developers who want to build products that work with these file types (think OpenOffice, etc), but the release of these file format details is sure to grab the attention of vulnerability hunters as well.
File fuzzers can now be tuned to the exact file specification, thus increasing their efficiency in finding possible security issues.
This is going to be an interesting topic to watch....
No comments:
Post a Comment