HomeSecurityGmail security filters can be bypassed!

Gmail security filters can be bypassed!

Some of Gmail's security features responsible for detecting malicious macros can be bypassed simply by splitting "trigger words" in the middle or along the string, according to what security researchers from SecureState have discovered.

Macros are pieces of script attached to Office files, which if the user allows it, can be executed and automate a series of processes.

Gmail security filters can be bypassed!

Created to simplify various tasks at work, macros have been abused since their inception by malware writers to perform malicious processes that lead to the installation of malware on targeted systems.

Microsoft blocks the automatic execution of these scripts, and email service providers have begun scanning attachments for documents containing macro scripts.

SecureState says that Gmail immediately identifies an Office document as malicious if the script uses certain keywords.

During their testing, Gmail detected an Excel file as malicious when the exploit code contained the word “powershell,” a very powerful Microsoft scripting utility that macros could call to interact with the underlying Windows operating system.

deletes malicious attachment

To their surprise, splitting the word, either by placing it on two lines or by splitting it into two strings, bypassed Gmail's security filter.

An attacker with knowledge of this trick only needed to adapt exploit by separating each possible call to the Powershell utility into two separate lines, as shown below.

Code:

Str = “powershe”

Str = Str + “ll.exe -NoP -sta -NonI -W Hidden -Enc JAB3”

Additionally, SecureState researcher Mike Benich also says that Gmail detects as malicious any macro scripts within Excel files that trigger the “workbook open” function.

The researcher says he was able to bypass this security feature by simply moving the exploit code inside a button.

The malicious code would not be executed as soon as the user enabled the macro feature / edited an infected Excel, but only after pressing another button.

Since Excel files can be quite complex, it's not too hard to imagine a user clicking a button to summarize the complex elements of a table into a chart. So, social engineering in Excel files is not difficult to achieve.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS