Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

do not fail on encrypted office documents #8

Conversation

conitrade-as
Copy link

This change set allows encrypted maldocs (e.g. .xlsx) with one password to be extracted from password protected archives with another password (e.g. .zip).

An example would be a .zip with the password of infected where the corresponding .xlsx document uses the well-known password VelvetSweatshop. An example could be found here: https://bazaar.abuse.ch/sample/1b09401fa79210a9667d030ca4b6960d468fd57697f7e8b5163f5d5d9b7d26d2/

@doomedraven doomedraven merged commit 4c3f4d8 into CAPESandbox:master Jul 8, 2021
@doomedraven
Copy link
Collaborator

thank you, just tested it and works, hm maybe we should introduce like subpassword?

doomedraven added a commit to doomedraven/karton-archive-extractor that referenced this pull request Jul 8, 2021
psrok1 pushed a commit to CERT-Polska/karton-archive-extractor that referenced this pull request Jul 9, 2021
* zipjail's fix for fchown

* do not fail on encrypted office documents when zip and doc pass are different

CAPESandbox/sflock#8
@conitrade-as conitrade-as deleted the hotfix/encrypted-archives-encrypted-maldocs branch July 12, 2021 09:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants