Hacker News new | ask | show | jobs
by prof_mm 2431 days ago
A Word document? Are you kidding me? Would a truly cyber-security conscious (i.e.: slightly paranoid) citizen download and open that, from the open internet, with a nation-state actor behind it?
3 comments

Anyone worth their grain of salt would download and analyze in a vm before executing on their own personal machine... I know I would. Didier Stevens[0] has a ton of tools for static analysis of these file types.

[0] https://blog.didierstevens.com/

It's docx. You can just unzip it to get a horribly XML but plaintext representation of the document.
Which format would you have preferred?
Plaintext would have sufficed
how can you inject an exploit from a plaintext file?
Didn't someone do that with notepad.exe recently? The demo spawned calc.exe from notepad.exe.