Beware of hidden fields in a Word document

Posted on 9 March, 2009
This item is filed under [MS Office Tricks, Security, Tips & Tricks]

March 9, 2009 · 0 comments

Did you know that there could be hidden fields in your Word documents which can be used to peer into your PC and even grab your files? Here’s how to prevent that from happening.

There is a little known trick in Microsoft that can allow malicious users to steal your private information. It could even allow someone to get access to the files on your PC. The trick uses Word Fields.

The legitimate use of Fields is to insert self-updating information into your Word documents, such as page numbers in a header or footer. However, some fields can be hidden and since you can’t see them, you can’t tell what they are doing.

One of these hidden fields is called IncludeText. It is generally a very useful fields which can insert Word documents or Excel spreadsheets into other Word documents. Unfortunately, the field can also be used maliciously. For example, suppose you receive a document from someone, which you are to edit and then return the document back to the sender. If it included a hidden IncludeText field with specific files and their locations on your hard disk, those files on your hard disk could be sent back to the document originator without your knowing it.

There are several ways to solve the problem. One is to install a Microsoft patch that fixes the vulnerability. For more information and to download it, go to http://support.microsoft.com/default.aspx?scid=kb;en-us;329748.

Another solution is to download a free tool called Hidden File Detector from http://www.wordsite.com/HiddenFileDetector.html. Once installed, it adds a new menu item, ‘Detect Hidden Files’, to Word’s Tools menu. When you choose it from the menu, a dialog box alerts you to any documents that have been inserted into a file by a Word Field that could be potentially be a spyware.

There is yet another way to find out, and this time without using any external tool. Just choose Edit>Links in the menu and see if there are any links to any files in your document. If there are no links, the Links option will be grayed out. If you do find them, you could delete them if needed or rather, if not needed.

Enjoyed this post? Share it with others.
  • email
  • Print
  • Digg
  • StumbleUpon
  • Technorati
  • Reddit
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • FriendFeed
  • BlinkList
  • Diigo
  • LinkedIn
  • Propeller
  • IndianPad
  • MySpace
  • Slashdot

Subscribe Now

If you enjoyed this post, you will definitely enjoy our others. Subscribe to the feed to get future posts delivered right to your mailbox or feedreader.

Powered by Thesis

Thesis Theme

An amazing WordPress Theme, nothing beats the versatility and SEO friendliness of the Thesis framework.

From beginners, to the most advanced WordPress developers, Thesis makes it easy for anyone to customize it.


Leave a Comment

Previous post:

Next post: