Open MalwareTips in Safari and tap Share. You may need to open the Page Menu first.
Choose Add to Home Screen. If it is not listed, use Edit Actions to add it.
Keep Open as Web App enabled if shown, then tap Add.
Android
Open MalwareTips in Chrome or another browser that supports app installation.
Open the browser menu and look for Install app, Install and create shortcut, or Add to Home screen.
Choose Install and confirm. Wording varies by browser.
Desktop
Chrome: use the install icon in the address bar, or the menu under Cast, save and share.
Edge: open the menu, then More tools, Apps and Install this site as an app.
Safari on Mac: choose Share or File, then Add to Dock. Firefox on Windows: look for the web apps button in the address bar.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
Keep up with your conversations
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
It is a good video with no controversial content, so it does not require many replies.
I agree that for most MT readers, the prevention against such attack vectors can also be interesting (even if slightly off topic).
Just finished watching the video, great explanation, thank you!
Question:
If you're looking at a .docx with a remote VSTO manifest, how much does the MOTW on the actual document mess with the .NET assembly execution? Like, if the manifest is sitting in a Trusted Sites zone but the doc itself is flagged for the Internet zone, which security policy actually takes the lead during the add-in loading phase?
Just finished watching the video, great explanation, thank you!
Question:
If you're looking at a .docx with a remote VSTO manifest, how much does the MOTW on the actual document mess with the .NET assembly execution? Like, if the manifest is sitting in a Trusted Sites zone but the doc itself is flagged for the Internet zone, which security policy actually takes the lead during the add-in loading phase?
Thank you. But regarding your question: Not entirely sure here because I did not test this, but the doc should be in protected view if it has Internet Zone mark of the web. And only if you leave protected view, the manifest trusted sites should become relevant.
This is the Malware Analysis subforum. The pinned topic says "This forum's main purpose is the discussion of malware analysis and reverse engineering techniques."
Recently browsing
Members who viewed this thread in the last 5 minutes