On TechRepublic: 10 dying IT skills
BNET Business Network:
BNET
TechRepublic
ZDNet

August 29th, 2008

A (Microsoft) Codename a day: Wringer

Posted by Mary Jo Foley @ 10:05 am

Categories: Code names, Corporate strategy, Office, Security

Tags: Codename, Microsoft Corp., Attack, MOICE, Microsoft Office, Security, Office Suites, Software, Mary Jo Foley

As I announced last week, I’m holding a short but sweet Microsoft codename contest this week, with the prize being a free signed copy of my Microsoft 2.0 book (which I will ship anywhere in the world to the winner).

Since I announced the rules and regulations, I’ve gotten more than a few interesting submissions. I was seeking from readers new (but real and existing) Microsoft codenames which I’ve had yet to detail as part of my growing Microsoft Codename list. I am running some of the best ones (as judged by yours truly) on my blog this week.

Without further ado, let’s get to it.

Codename of the day: Wringer

Best guess on what it is: MOICE - the Microsoft Office Isolated Conversion Environment

Meaning/context of the codename: The MOICE project isn’t new, but the codename and its origins were new to me. MOICE is designed to “wring out” malicious content from Office documents.

Hold onto your hats for the full explanation from Software Security Engineer Robert Hensing’s blog:

“(B)asically what MOICE does is it hijacks the file associations in the registry and redirects them to a process called ‘MOICE.EXE’.  This process basically spawns the Office 2007 file format converter to up-convert the double-clicked Office 2003 document to the new Open XML file format.  Oh and the converter runs in its own desktop with a super-locked down token (Dave is the freaking man!).  Why run the converter in its own desktop with a super restricted token?  Simple - what if the act of converting the file leads to an exploitable bug and / or code execution.  This is effectively dropping the rights of the logged on user to *below* standard user levels in order to do the file conversion.  Anyhoo - after the file is up-converted to the new Office 2007 file format - the theory is that the vulnerability will have been ‘wrung’ out (indeed the code name for this project was ‘Wringer’).”

Back story: Office remains a big hacker target — something of which Microsoft is quite aware. As Hensing blogged:

“(I)t’s no secret that Office was used in some targetted attacks last year . . . some attacks involving 0-day vulnerabilities for which our customers had no way of protecting themselves (short of not opening documents). Had MOICE been available these customers could have deployed it to mitigate these attacks.”

Additional info: The National Security Agency published a fact sheet on Wringer, as well as a Wringer deployment guide.

Got a Microsoft code name you’ve been wondering about? Send it my way. All submitters will be kept confidential.Meanwhile, if you want to keep track of the full month’s worth of Microsoft code names I end up posting, bookmark this “Microsoft Codenames” page.

“(B)asically what MOICE does is it hijacks the file associations in the registry and redirects them to a process called ‘MOICE.EXE’.  This process basically spawns the Office 2007 file format converter to up-convert the double-clicked Office 2003 document to the new Open XML file format.  Oh and the converter runs in its own desktop with a super-locked down token (Dave is the freaking man!).  Why run the converter in its own desktop with a super restricted token?  Simple - what if the act of converting the file leads to an exploitable bug and / or code execution.  This is effectively dropping the rights of the logged on user to *below* standard user levels in order to do the file conversion.  Anyhoo - after the file is up-converted to the new Office 2007 file format - the theory is that the vulnerability will have been ‘wrung’ out (indeed the code name for this project was ‘Wringer’).”

Back story: Office remains a big hacker target — something of which Microsoft is quite aware. As Hensing blogged:

“(I)t’s no secret that Office was used in some targetted attacks last year . . . some attacks involving 0-day vulnerabilities for which our customers had no way of protecting themselves (short of not opening documents). Had MOICE been available these customers could have deployed it to mitigate these attacks.”

Additional info: The National Security Agency published a fact sheet on Wringer, as well as a Wringer deployment guide.

Got a Microsoft code name you’ve been wondering about? Send it my way. All submitters will be kept confidential.

Mary Jo FoleyMary Jo has covered the tech industry for more than 20 years. Don't miss a single post. Subscribe via Email or RSS. You can also follow Mary Jo on Twitter.

Got a tip? Send Mary Jo your rants, rumors, tips and tattles. For disclosure on Mary Jo's industry affiliations, click here or to see Mary Jo's full profile click here.

  • Talkback
  • Most Recent of 5 Talkback(s)
RE: A (Microsoft) Codename a day: Wringer
TOD Converter,
VOB Converter for Mac,
... (Read the rest)
Posted by: hqconverter Posted on: 04/09/09 You are currently: a Guest | | Terms of Use
Microsoft ain't normal  BALTHOR | 08/29/08
Customary to link the source?  spongbo | 08/29/08
link  Mary Jo FoleyZDNet Moderator | 08/30/08
RE: A (Microsoft) Codename a day: Wringer  oldgeeker | 08/31/08
RE: A (Microsoft) Codename a day: Wringer  hqconverter | 04/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Order Microsoft 2.0

Pre-order Microsoft 2.0

Order 'Microsoft 2.0' by Mary Jo Foley at Amazon.com.

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

Introducing SmartPlanet

  • Find thought-provoking progressive ideas on topics that intersect with technology, business and life. Visit Today
  • Technology, perspective, and insights shaping the world
  • Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large. Go to SmartPlanet
advertisement
Click Here