{"id":6882,"date":"2019-11-19T01:02:17","date_gmt":"2019-11-19T01:02:17","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=6882"},"modified":"2019-11-19T12:14:43","modified_gmt":"2019-11-19T12:14:43","slug":"mindmap-software-as-an-attack-vector","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2019\/11\/19\/mindmap-software-as-an-attack-vector\/","title":{"rendered":"Mindmap software as an attack vector"},"content":{"rendered":"\n<p>Looks like mindmap software could be used to deliver bad stuff; interaction is still required, but could be an interesting attack vector especially that it&#8217;s a popular type of software in a corp. environment:<\/p>\n\n\n\n<p><strong>Xmind<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"479\" height=\"450\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/xmind.gif\" alt=\"\" class=\"wp-image-6883\"\/><\/figure>\n\n\n\n<p><strong>FreeMind<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"414\" height=\"377\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/freemind.gif\" alt=\"\" class=\"wp-image-6886\"\/><\/figure>\n\n\n\n<p><strong>MindView<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"569\" height=\"592\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/mindview.gif\" alt=\"\" class=\"wp-image-6888\"\/><\/figure>\n\n\n\n<p><strong>MindManager<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"714\" height=\"592\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/mindmanager.gif\" alt=\"\" class=\"wp-image-6890\"\/><\/figure>\n\n\n\n<p>The latter allows attaching actual binary files as well, but an attempt to launch them will end up with the following dialog box shown:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" loading=\"lazy\" width=\"437\" height=\"206\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/mindmanager_warning.png\" alt=\"\" class=\"wp-image-6891\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/mindmanager_warning.png 437w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2019\/11\/mindmanager_warning-300x141.png 300w\" sizes=\"(max-width: 437px) 100vw, 437px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Looks like mindmap software could be used to deliver bad stuff; interaction is still required, but could be an interesting attack vector especially that it&#8217;s a popular type of software in a corp. environment: Xmind FreeMind MindView MindManager The latter &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2019\/11\/19\/mindmap-software-as-an-attack-vector\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[15,46,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6882"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=6882"}],"version-history":[{"count":5,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6882\/revisions"}],"predecessor-version":[{"id":6892,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/6882\/revisions\/6892"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=6882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=6882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=6882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}