Saturday, December 4, 2021

Copy and paste multiple formats in Edge, beat them to the punch, on-the-fly metadata extraction

Microsoft wants to improve copy and paste in Edge and Chrome for Windows 11. This recycled idea particular useful for Office product suite. One need to cut and paste Excel spread sheets and images into Word documents and vice-versa without loosing fidelity of the original object being copied. But there are some major security concerns, that would have to be addressed. Because some object formats can carry viruses. 

You can beat Microsoft to the punch by getting the only Clipboard PlainText Powertool that can extract the metadata from Office documents on-the-fly. 

 Preview of metadata info put on clipboard for a .DOCX and .MP3 file when copying or moving using Clipboard Powertool.

Copied/Moved 
DOCX "Standard Release Form.docx"  2pgs 42.6KB Title:"Microsoft Word - Standard Release Form.doc" Author:"aaggarwa" Company:"John Wiley and Sons, Inc." Mon 04-Jan-21  11:30AM "H:\Downloads2021\Standard Release Form.docx"
MP3 "01 Genesis.mp3"  5,512KB 44kHz 00:03:55 Title:"Genesis" Album:"Justice" Artist:"Justice" Year:2007 Sat 08-Mar-14  9:43PM "C:\Users\Markus\Music\iTunes\iTunes Media\Music\Justice\Justice\01 Genesis.mp3" - 

Get Clipboard Plaintext Powertool here.






Wednesday, November 24, 2021

Efficient removal of Unicode hidden characters that backdoors your Javascript code

From the great post The Invisible JavaScript Backdoor – Certitude Blog and Invisible characters could be hiding backdoors in your JavaScript code  - bleepingcomputer.com invisible characters one could also introduce backdoors using Unicode characters that look very similar “Invisible Character Attacks” and “Homoglyph Attacks“. This technique has been around awhile using the have Unicode bidirectional mechanism (Bidi). As the article states, that messing with Unicode to hide vulnerable or malicious code is not a new idea (also using invisible characters) and Unicode inherently opens up additional possibilities to obfuscate code. We believe that these tricks are quite neat though, which is why we wanted to share them. In our experience non-ASCII characters are pretty rare in code. It might therefore be a good idea to disallow any non-ASCII characters. As article states, we mostly see non-ASCII characters being substituted with normalized ASCII characters (e.g. ä → ae, ß → ss) or removal them completely. But how ? 

Some self promotion, some hard times my friends.

My Clipboard PlainText Powertool provides easy text transformations for these substitutions for code de-obfuscation for Javascript (or any languages) to reveal  “Invisible Character Attacks” and “Homoglyph Attacks“. 

Here some transformations you can perform in 1-click; 

  1. Paste ANSI text (ISO-8859-1, Western languages), moins les caractères de contrôle && non imprimable
  2. Paste Unicode universal text (all languages), replacing all non-printable characters with ♦
  3. Paste Unicode universal text (all languages), striping all non-printable characters (most general)
  4. Paste plain ASCII text with normalized substitutions. eg. Æ ⇒ AE, ß⇒ss, è⇒e
  5. Paste plain ASCII text, striping bad control characters && formatting (most restrictive)
  6. Paste plain text ASCII,  extended range (Latin-1 Supplement) translated. eg. Ã⇒A(tilde)


❖ Get  Clipboard PlainText Powertool  comes with 200+ clip transformations and 20 individual PowerTools features Notepad2 (everything you wanted in Notepad).

Tuesday, October 26, 2021

2021 Pro Tip : Convert OneDrive Share Link to Download Link

Here's how to convert OneDrive Share Link to a instant download link. This follows from my original post in 2014 when I first discovered this trick.


  1. Click on desired file and click Share (at Top) to reveal Copy link button. Click. 



  2. This will reveal Microsoft shortened URL to the file. Copy.



  3. Goto https://unshorten.me/ or similar service and paste link e.g.
    https://1drv.ms/u/s!AsRPggdGwZFcjWhqmIY9K_tzLnQI?e=1o1vOQ
    to get expanded URL.




  4. Copy destination URL and change /redir? to /download?

    For example, 

    https://onedrive.live.com/redir?resid=5C91C14607824FC4!1768&authkey=!AGqYhj0r-3MudAg&e=1o1vOQ

    to 

    https://onedrive.live.com/download?resid=5C91C14607824FC4!1768&authkey=!AGqYhj0r-3MudAg&e=1o1vOQ


  5. Use this link for an instant direct download of the shared file. This buy passes the preview pane in OneDrive.com. Done.