Help - Search - Members - Calendar
Full Version: Mail Recipient (as Attachment)
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
Sacles
Hello,

I use The Bat! and Word (2003).

1. Word is Trusted and The Bat! Untrusted (Usual situation)

If I try to send a document with the function "Mail Recipient (as Attachment)", this operation does not work.

2. Word as Untrusted and The Bat! Untrusted (or Word Trusted and The Bat! Trusted)

If I try to send a document with the function "Mail Recipient (as Attachment)", this operation works correctly.

Why?
Ilya Rabinovich
You have to do following:
1. Clean up "Events log" sheet ("Delete all"->"Apply").
2. Reproduce the issue.
3. Export DW's logs ("Events log"->"Export") into a file and post here.

I suspect it's about inability to communicate with COM between trusted and untrusted zone (it's very dangerous), but have to make sure in it.
Sacles
I do not have time now. I will do this this afternoon.
Sacles
Details:
1. When I start "Mail Recipient (as Attachment)" in Word, Nothing happens (Only the hourglass). After a few minutes, I stop Word from the task manager.

2. If I try to send a Word file by a right click on the file> Send to> The Bat!, Everything is normal.

There are not many things in the log.

Excuse me for my bad English.

Sacles
If I set Outlook Express by default, I have no problem to send a document from Word (with "Mail Recipient (as Attachment).

The problem seems to be related to The Bat!

I know that The Bat! uses its own file Mapi32.dll
Ilya Rabinovich
"module C:\Program Files\The Bat!\thebat.exe, Attempt to open process C:\Program Files\Microsoft Office\Office10\WINWORD.EXE".

Looks like TheBat is using a kind of dangerous "open process" call of MS Word process, I assume, in order to inject some data into it. As Word is trusted, it's just impossible for security reasons.
Sacles
QUOTE ("Ilya Rabinovich")
I suspect it's about inability to communicate with COM between trusted and untrusted zone (it's very dangerous), but have to make sure in it.


""module C:\Program Files\The Bat!\thebat.exe, Attempt to open process C:\Program Files\Microsoft Office\Office10\WINWORD.EXE".

This situation is dangerous or not?

Ilya Rabinovich
QUOTE (Sacles @ Aug 21 2009, 03:26 PM) *
""module C:\Program Files\The Bat!\thebat.exe, Attempt to open process C:\Program Files\Microsoft Office\Office10\WINWORD.EXE".
This situation is dangerous or not?

This is the way TheBat works, but I just can't allow it do to security reasons.
Sacles

A solution is possible?
Ilya Rabinovich
Yes, but on TheBat's side. I can do nothing, unfortunately, as far as I remember, I tried, but failed.
Sacles
What should I ask at The Bat team?
Ilya Rabinovich
As them if they can get read of trusted process memory modifications during the task. It's forbidden with any sandbox.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.