Jump to content

WinRAR Cracked - 14 year old Remote Code Execution flaw found

rcmaehl
8 minutes ago, Syntaxvgm said:

I'm not aware of it being able to create rars though, last time I checked it didn't because the license doesn't allow that? 

Just realized that I misread the last post I responded to as being able to open RAR files, instead of create them.  I just checked, and it can create TAR files, but not RARs.

Link to comment
Share on other sites

Link to post
Share on other sites

https://research.checkpoint.com/extracting-code-execution-from-winrar/

 

the actual writeup for it.  very interesting

How do Reavers clean their spears?

|Specs in profile|

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, Mayushii said:

Lol people still use winrar?

Yes, some of us do.

Hand, n. A singular instrument worn at the end of the human arm and commonly thrust into somebody’s pocket.

Link to comment
Share on other sites

Link to post
Share on other sites

19 hours ago, Eaglerino said:

why do people use winrar over 7zip

what is the point? Winrar does the job

Link to comment
Share on other sites

Link to post
Share on other sites

I feel it's worth pointing out that this isn't necessarily a WinRAR bug, attention getting title notwithstanding.  The issue is the DLL used to open ACE archives, which has now been removed as of the latest beta.  In theory, this could affect any archive software which uses that same DLL.  And since ACE is a dead format with no further development, the likelihood of the issue actually being corrected (rather than the feature removed) is somewhere between slim and none.

Link to comment
Share on other sites

Link to post
Share on other sites

19 hours ago, Mayushii said:

Lol people still use winrar?

Only way to create RARs, so a lot of people use it even if they have 7zip as primary day to day use. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Have they made a Winrar skin for 7zip yet.

Desktop: 7800x3d @ stock, 64gb ddr4 @ 6000, 3080Ti, x670 Asus Strix

 

Laptop: Dell G3 15 - i7-8750h @ stock, 16gb ddr4 @ 2666, 1050Ti 

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Raskolnikov said:

Have they made a Winrar skin for 7zip yet.

You’ll know they had when 7zip’s splash screen tells you your free trial has expired.

Link to comment
Share on other sites

Link to post
Share on other sites

On 2/21/2019 at 3:19 AM, Eaglerino said:

why do people use winrar over 7zip

Because WinRAR allows Cascaded Context Menu and 7zip doesn't. Personally I hate my right click being longer than my desktop.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

On 2/21/2019 at 12:20 AM, williamcll said:

But you could be using 7zip instead.

Sure, but in a future news topic about a 7zip bug we'll say "you could use Winzip", then "Windows native Zip", then "Winrar"...

They're all fine while there's no bug, though. They just workTM

 

On 2/21/2019 at 11:31 AM, RejZoR said:

Why people use anything else than 7zip?

Maybe because

On 2/21/2019 at 11:31 AM, RejZoR said:

LZMA2 is the most advanced compression algorithm at the moment. It's second best right after ZPAQ, but with realistically usable speeds. ZPAQ saves few extra megabytes, but takes like 10x longer even on 12 thread "powerhouse".

is something that 0,000001% of the population will know or even understand?

I'm pretty sure that the vast majority of computer users aren't thinking about the efficiency of LZMA2 when installing software in their devices, but rather googling "I have rar, how to open?".

 

I mean, why do people use Adobe Acrobat?

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, SpaceGhostC2C said:

Sure, but in a future news topic about a 7zip bug we'll say "you could use Winzip", then "Windows native Zip", then "Winrar"...

They're all fine while there's no bug, though. They just workTM

 

Maybe because

is something that 0,000001% of the population will know or even understand?

I'm pretty sure that the vast majority of computer users aren't thinking about the efficiency of LZMA2 when installing software in their devices, but rather googling "I have rar, how to open?".

 

I mean, why do people use Adobe Acrobat?

Then who are still the "geeks" who use RAR so that noobs need to look for it? I don'tknow, asking for a friend and all that...

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, handymanshandle said:

Exactly what would the point of cracking WinRAR serve? That 40 day trial lasts forever to the best of my knowledge.

It was not cracked in that kind of way :P

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×