OpenOffice password crack open to abuse

By Tom Espiner, ZDNet UK
Tuesday, April 24, 2007 07:29 AM

Security experts have warned that password recovery tools for OpenOffice, the open-source application suite, are vulnerable to abuse.

The release of version 1.0.4 of Intelore's OpenOffice Password Recovery software last week allows IT managers and systems administrators to recover OpenOffice passwords and discard formatting and editing restrictions--for example, locked cell protection and permissions. The software allows password recovery through brute force and dictionary-based attacks, or a combination of both.

"Even if you have lost passwords for all your OpenOffice programs and documents, Intelore's solution can help you quicker than any similar program--OpenOffice Password Recovery supports simultaneous processing of several recovery projects with different attack profiles," said Dmitry Rozenbaum, chief executive officer of Intelore.

Although password recovery tools for Microsoft applications have been available for at least six years, OpenOffice Password Recovery is one of the first commercially available tools for open-source products. But security experts have warned that such tools could be open to abuse.

"These kinds of tools can be used for both good and bad," said Graham Cluley, senior technology consultant for security vendor Sophos. "It's a grey area in software. Cottage industries for such tools are mushrooming. These applications can help people, but in the wrong hands they're a bit of a security concern." Cluley added that IT managers could set policies about who could have access to such tools on a business network.

Paul Wood, senior analyst at e-mail security vendor MessageLabs, said that it opened a possible attack vector from disgruntled employees. He said: "One attack vector is if a rogue employee has access to file-share password-protected documents. They can copy them, take them offline, and brute-force them at their leisure." Wood added that companies should lock down privileges, and consider encryption for sensitive documents.

OpenOffice Password Recovery version 1.0.4 is available to download for evaluation. The full business version costs US$129. The product offers Unicode support and allows for recovery of multi-language passwords. OpenOffice Password Recovery version 1.0.4 can also recover a password containing typing errors, according to Interlore.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Create your own yum repository

Open Source

Learn how to create your own yum repository with the createrepo tool. One thing it allows you to do is distribute specialized packages within an organization.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Unnecessary distraction

Blog thumbnail

If not for the weird story that President Arroyo underwent a breast implant operation in a local hospital, I’m pretty sure the heat and public ridicule would not have abated..... by Melvin G. Calimag

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web