Hacker of WinRAR flaw exposure but embedded and baleful file

In recent years, software safety topological features is very austere, all sorts of flaw appear often, caused great menace to user data and privacy. Last year, safe researcher of Check Point Software discovered flaw of software of a WinRAR, exploit this loophole, the hacker is OK will baleful file is embedded among them. According to the convention of safe industry, near future of this one flaw by outside intermediary exposure comes out, and relevant and safe orgnaization expresses, had discovered more than 100 means that use this flaw to have charge.

Hacker of WinRAR flaw exposure but embedded and baleful file

Specific for, what this flaw uses is ACE format file, before this because of WinRAR person the limits of authority that lost source code of visit UNACEV2.DLL library, so the decision abandons the support of pair of ACE file formats, flaw arises below this kind of circumstance.

Although the WinRAR of newest version already repair this flaw, but quite big the user of one part has not replaced software newest edition, once in action can make individual information suffers menace.

Nevertheless, since be to pass the means of embedded and baleful file to exploit loophole, should be opposite so means actually relatively a few simpler also. If unidentified ACE document is obtained in your mailbox, do not want informal solution to compress please open a file, can be atttacked probably by the hacker otherwise.

In addition, the method that prevents this kind of attack is reach WinRAR newlier as soon as possible version of newest WinRAR 5.70 Beta 1.

The editor is commented on

Use what is compressing software flaw to have charge new issue, in nevertheless still a lot of people are met, enrol, the unidentified file that the reason depends on everybody going up to mail or webpage was not on guard consciousness. And some compress a file send an user with the name such as belle, lottery, be ignored more easily by everybody.

ZhongGuanCun of APP shop search is online, see newest 2018 mobile phone, jotter evaluate seniority

未经允许不得转载:News » Hacker of WinRAR flaw exposure but embedded and baleful file