Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. ZIP or Rar argument may take nose dive....

ZIP or Rar argument may take nose dive....

Scheduled Pinned Locked Moved The Lounge
com
6 Posts 6 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    B Offline
    Bradml
    wrote on last edited by
    #1

    http://www.securityfocus.com/bid/22447[^] Turns our Winrar password protection is no longer effective.

    D C 2 Replies Last reply
    0
    • B Bradml

      http://www.securityfocus.com/bid/22447[^] Turns our Winrar password protection is no longer effective.

      D Offline
      D Offline
      Dominik Reichl
      wrote on last edited by
      #2

      Bradml wrote:

      Turns our Winrar password protection is no longer effective.

      To my understanding, the bug is simply a buffer overflow in the Unrar decryption code. From the report: "Unrar is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. An attacker can exploit this issue to execute arbitrary code with the privileges of the user opening the archive." This does not mean that the password protection would be ineffective! When decrypting, the Unrar tool could maybe crash or execute malicious code, but it does not break the encryption (which would be far more critical in my opinion).


      Too many passwords to remember? Try KeePass Password Safe!

      P 1 Reply Last reply
      0
      • D Dominik Reichl

        Bradml wrote:

        Turns our Winrar password protection is no longer effective.

        To my understanding, the bug is simply a buffer overflow in the Unrar decryption code. From the report: "Unrar is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer. An attacker can exploit this issue to execute arbitrary code with the privileges of the user opening the archive." This does not mean that the password protection would be ineffective! When decrypting, the Unrar tool could maybe crash or execute malicious code, but it does not break the encryption (which would be far more critical in my opinion).


        Too many passwords to remember? Try KeePass Password Safe!

        P Offline
        P Offline
        peterchen
        wrote on last edited by
        #3

        Far more critical than installing a backdoor? I agree that circumventing the password protection would help "casual abuse" i.e. the hole is wider but less deep.


        Developers, Developers, Developers, Developers, Developers, Developers, Velopers, Develprs, Developers!
        We are a big screwed up dysfunctional psychotic happy family - some more screwed up, others more happy, but everybody's psychotic joint venture definition of CP
        Linkify!|Fold With Us!

        1 Reply Last reply
        0
        • B Bradml

          http://www.securityfocus.com/bid/22447[^] Turns our Winrar password protection is no longer effective.

          C Offline
          C Offline
          Chris Losinger
          wrote on last edited by
          #4

          there's an argument? i thought the situation was pretty clear: pirates use RAR, everyone else uses ZIP

          image processing toolkits | batch image processing | blogging

          S P 2 Replies Last reply
          0
          • C Chris Losinger

            there's an argument? i thought the situation was pretty clear: pirates use RAR, everyone else uses ZIP

            image processing toolkits | batch image processing | blogging

            S Offline
            S Offline
            S Douglas
            wrote on last edited by
            #5

            Chris Losinger wrote:

            pirates use RAR

            :) It must be Friday, took me a minute.


            I'd love to help, but unfortunatley I have prior commitments monitoring the length of my grass. :Andrew Bleakley:

            1 Reply Last reply
            0
            • C Chris Losinger

              there's an argument? i thought the situation was pretty clear: pirates use RAR, everyone else uses ZIP

              image processing toolkits | batch image processing | blogging

              P Offline
              P Offline
              Phillip Martin
              wrote on last edited by
              #6

              Not that clear. Oim not a scurvey Poirate, and Oi use WinRar (Sorry, feeble attempt at a text pirate accent :) ) - Phil

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups