Logo white

Peter M. Groen / oletools

Sign in
  • Sign in
  • Project
  • Files
  • Commits
  • Network
  • Graphs
  • Milestones
  • Issues 0
  • Merge Requests 0
  • Labels
  • Wiki
  • Commits 1,521
  • Compare
  • Branches 1
  • Tags 0
  • oletools
23 May, 2018
2 commits
  • oleform: uncompressed strings still have the right length
    2c8866de
    Vincent Brillault authored
    2018-05-23 20:37:53 +0200  
    Browse Code »
  • WIP: oleform: implement other types of stored controls
    9d2795aa
    Vincent Brillault authored
    2018-05-23 00:04:49 +0200  
    Browse Code »

22 May, 2018
1 commit
  • oleform: fail cleanly in case of unsupported content
    425a038a
    Vincent Brillault authored
    2018-05-22 22:34:30 +0200  
    Browse Code »

17 May, 2018
2 commits
  • Merge remote-tracking branch 'origin/master'
    1b3768ad
    decalage2 authored
    2018-05-17 22:20:10 +0200  
    Browse Code »
  • rtfobj: fixed issue #273, bytes constants instead of str
    9f01ec8f
    decalage2 authored
    2018-05-17 22:19:53 +0200  
    Browse Code »

15 May, 2018
2 commits
  • Merge pull request #312 from ShiaoQu17/patch-1 ...
    d076729d
    Update clsid.py
    Philippe Lagadec authored
    2018-05-15 11:28:59 +0200  
    Browse Code »
  • Update clsid.py ...
    dcd7536d
    ref: https://support.office.com/en-us/article/flash-silverlight-and-shockwave-controls-blocked-in-office-2016-55738f12-a01d-420e-a533-7cef1ff6aeb1
    Shiao Qu authored
    2018-05-15 17:25:23 +0800  
    Browse Code »

14 May, 2018
1 commit
  • readme: added link to DARKSURGEON
    a4215ff3
    Philippe Lagadec authored
    2018-05-14 09:12:17 +0200  
    Browse Code »

13 May, 2018
1 commit
  • olevba3: added support for Word/PowerPoint 2007+ XML (FlatOPC) - issue #283
    2356048d
    decalage2 authored
    2018-05-13 23:12:16 +0200  
    Browse Code »

11 May, 2018
1 commit
  • msodde: updated version after PR #275
    ae4f1882
    decalage2 authored
    2018-05-11 23:06:58 +0200  
    Browse Code »

10 May, 2018
5 commits
  • Merge pull request #275 from christian-intra2net/csv-formula-extension ...
    7f19e632
    Csv formula extension
    Philippe Lagadec authored
    2018-05-10 22:05:42 +0200  
    Browse Code »
  • Merge remote-tracking branch 'origin/master'
    bb243c78
    decalage2 authored
    2018-05-10 16:19:43 +0200  
    Browse Code »
  • rtfobj: fixed issues #303 #307, several destination cwords were incorrect
    2f4b6e39
    decalage2 authored
    2018-05-10 16:19:21 +0200  
    Browse Code »
  • Merge pull request #306 from ShiaoQu17/patch-2 ...
    fbf1621c
    Update clsid.py (CVE-2018-8174)
    Philippe Lagadec authored
    2018-05-10 10:49:30 +0200  
    Browse Code »
  • Update clsid.py ...
    787c0c68
    CVE-2018-8174: https://securelist.com/root-cause-analysis-of-cve-2018-8174/85486/
    
    Uses the same technique as CVE-2017-0199 in the RTF document.
    URL Moniker ---> Media Negotiation(server returns content-type: text/html, CVE-2017-0199 server returns content-type: application/hta, which was already blocked by "IActivationFilter" in MSO.DLL) ---> HTML triggers a vulnerability in vbscript.dll(CVE-2018-8174)
    Shiao Qu authored
    2018-05-10 13:06:39 +0800  
    Browse Code »

09 May, 2018
3 commits
  • clsid: added more CLSIDs (updated issue #299)
    7888b62a
    decalage2 authored
    2018-05-09 13:05:14 +0200  
    Browse Code »
  • Merge pull request #305 from ShiaoQu17/patch-1 ...
    7b7fb85a
    remove a duplicated key
    Philippe Lagadec authored
    2018-05-09 08:48:56 +0200  
    Browse Code »
  • remove a duplicated key
    c19a5c25
    Shiao Qu authored
    2018-05-09 11:13:37 +0800  
    Browse Code »

08 May, 2018
3 commits
  • clsid: added more CLSIDs (issue #304)
    0fa1261a
    decalage2 authored
    2018-05-08 23:11:00 +0200  
    Browse Code »
  • clsid: added more CLSIDs (issue #299), merged and sorted
    1016bf9e
    decalage2 authored
    2018-05-08 22:52:04 +0200  
    Browse Code »
  • clsid: sorted lines
    02bd7d92
    decalage2 authored
    2018-05-08 22:38:42 +0200  
    Browse Code »

07 May, 2018
1 commit
  • clsid: added CLSID for Excel sheet (issue #298)
    193f9efa
    decalage2 authored
    2018-05-07 22:46:50 +0200  
    Browse Code »

03 May, 2018
2 commits
  • unittest: test extended msodde CSV formula
    bd3ab499
    Christian Herdtweck authored
    2018-05-03 13:53:09 +0200  
    Browse Code »
  • msodde: extend CSV regex to capture other fomulae
    5bd15a27
    Christian Herdtweck authored
    2018-05-03 13:53:09 +0200  
    Browse Code »

30 Apr, 2018
1 commit
  • rtofbj: handle the "\'" obfuscation trick - issue #281
    9201fe43
    decalage2 authored
    2018-04-30 07:27:53 +0200  
    Browse Code »

27 Apr, 2018
2 commits
  • rtofbj: extract and display the CLSID of OLE objects
    4901744d
    decalage2 authored
    2018-04-27 13:31:39 +0200  
    Browse Code »
  • clsid: added a few more CLSIDs (issue #290)
    13945508
    decalage2 authored
    2018-04-27 13:31:07 +0200  
    Browse Code »

25 Apr, 2018
2 commits
  • oleid: bumped version to 0.53dev6
    981ddc5c
    decalage2 authored
    2018-04-25 06:14:25 +0200  
    Browse Code »
  • Merge pull request #194 from samiraguiar/oleid-openxml-encryption ...
    7c34036c
    oleid: detect OpenXML encryption
    Philippe Lagadec authored
    2018-04-25 05:59:40 +0200  
    Browse Code »

23 Apr, 2018
1 commit
  • rtfobj: fixed issue #292, \margSz must be treated as a destination control word
    08454248
    decalage2 authored
    2018-04-23 23:12:27 +0200  
    Browse Code »

18 Apr, 2018
4 commits
  • Merge remote-tracking branch 'origin/master'
    676b3446
    decalage2 authored
    2018-04-18 22:10:51 +0200  
    Browse Code »
  • oledir/clsid: added known-bad CLSIDs from Cuckoo sandbox (issue #290)
    9d064030
    decalage2 authored
    2018-04-18 22:10:31 +0200  
    Browse Code »
  • Merge pull request #289 from christian-intra2net/msodde-no-error-condition ...
    3d75da3e
    msodde: Determine when error condition actually is one
    Philippe Lagadec authored
    2018-04-18 11:13:32 +0200  
    Browse Code »
  • msodde: Determine when error condition actually is one ...
    a5ba31bf
    msodde would sometimes complain that something should be an error condition.
    Determined that most of these are not and raise proper error for those that
    really are an error.
    Christian Herdtweck authored
    2018-04-18 09:33:49 +0200  
    Browse Code »

17 Apr, 2018
2 commits
  • Merge pull request #288 from enkelli/fix-str-has-no-attrib-decode ...
    40342031
    Fix AttributeError: 'str' object has no attribute 'decode'.
    Philippe Lagadec authored
    2018-04-17 09:43:51 +0200  
    Browse Code »
  • Fix AttributeError: 'str' object has no attribute 'decode'. ...
    41a30509
    extract_macros() returns vba_code as bytes or string (string only for
    OpenXML/PPT -- open_text() decodes bytes to string).
    
    This way it is already implemented in process_file() and process_file_json().
    
    Sample hash: 586DB43601FB55E89E67DFE569E1E9983779722ED47A8E1F23ADF54D04D3DF4B
    Pavol Plaskoň authored
    2018-04-17 09:00:13 +0200  
    Browse Code »

15 Apr, 2018
2 commits
  • setup: added new common package
    595e0c5a
    decalage2 authored
    2018-04-15 23:12:07 +0200  
    Browse Code »
  • olevba 0.53dev4: added support for Word/PowerPoint 2007+ XML format, aka Flat OPC (issue #283)
    b7b13bb5
    decalage2 authored
    2018-04-15 23:10:20 +0200  
    Browse Code »

13 Apr, 2018
2 commits
  • oledir: moved KNOWN_CLSIDs to common.clsid
    31b535f3
    decalage2 authored
    2018-04-13 22:37:31 +0200  
    Browse Code »
  • Merge pull request #282 from ShiaoQu17/master ...
    009b32d9
    Update oledir.py
    Philippe Lagadec authored
    2018-04-13 22:26:56 +0200  
    Browse Code »