Science and Tech

They show that Microsoft SharePoint can scan encrypted ZIP folders for ‘malware’

They show that Microsoft SharePoint can scan encrypted ZIP folders for 'malware'

May 16. (Portaltic/EP) –

The collaboration platform focused on organizations and companies Microsoft SharePoint has a new ability to access and analyze the contents of compressed ZIP folders despite being password protected.

The ZIP is a file format that is used as a container folder for one or more compressed files, so that it can reduce its size and facilitate its transmission from one unit to another, for example, a hard drive.

Now the principal researcher at security-focused hardware and software company Sophos, Andrew Brandt, has discovered that Microsoft Sharepoint has the ability to analyze the content of these folders encrypted and notify users in case of discovering malicious ‘software’ included in them.

“Malware detected. Some commands are not available”, can be seen in the notification that he has shared on Twitter, which includes the icon of a ZIP folder at the top, as well as a button that directs the user to “learn more” about this problem.

Brandt explains that he discovered this notification on the Microsoft service because it has “a bunch” of password-encrypted ZIPs that contain malware. “My usual method of sharing is to upload those ZIPs to a SharePoint directory,” he has acknowledged.

The researcher points out that, although understands “perfectly that this be done For users who are not malware analysts, this form of intrusion could become “a big problem” for users using this type of software.

According to Brandt, this new Microsoft SharePoint filter, which the technology developer itself has not reported through its official channels or in its security solutions section, “will affect the ability of researchers ‘malware’ to do its job”.

Source link