@marcan42 I wouldn’t necessarily say can’t. Also that’s only 1 other file type- PK
-
-
Oh, I understand it's only one other filetype. But many news reports do not. And I doubt it will be done any time soon.
1 reply 0 retweets 0 likes -
The problem with PK is getting the compressed data collision and still have the decompressed data make sense.
1 reply 0 retweets 0 likes -
Replying to @MalwareJake @init99
PK has plenty of uncompressed headers to play around with, plus the data itself can be uncompressed.
1 reply 0 retweets 0 likes -
I understand the format, but does the MS Office standard support he full range of PK options?
1 reply 0 retweets 0 likes -
Replying to @MalwareJake @init99
I would be rather surprised if it didn't support things like uncompressed mode and comments (if only to ignore them)
1 reply 0 retweets 0 likes -
Replying to @marcan42 @MalwareJake
good point re news. I’d guess
@marcan42 is right on the uncomp blocks. Can test in May when the Shattered PoC is out1 reply 0 retweets 0 likes -
Replying to @init99 @MalwareJake
Shattered PoC isn't going to help you here unless you have $100k to burn on Amazon. PDF-wise we already know the story.
1 reply 0 retweets 0 likes -
But you can try to construct a pseudo-collision template for PK/OOXML now if you want (just add $100k to make it real)
1 reply 0 retweets 0 likes -
It's not completely trivial though, e.g. there are data CRCs and you can't collide CRCs (math works against you here)
1 reply 0 retweets 0 likes
(if the CRC32s of the collision blocks don't match then no arbitrary identical data appended will make them match)
-
-
But I think it's quite likely that you can pull some tricks with PK metadata, not just payload data.
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.