rhabarba to Technology@beehaw.orgEnglish • 10 months agoWinRAR zero-day exploited since April to hack trading accountswww.bleepingcomputer.comexternal-linkmessage-square22fedilinkarrow-up1108cross-posted to: hackernews@derp.footechnews@radiation.party
arrow-up1108external-linkWinRAR zero-day exploited since April to hack trading accountswww.bleepingcomputer.comrhabarba to Technology@beehaw.orgEnglish • 10 months agomessage-square22fedilinkcross-posted to: hackernews@derp.footechnews@radiation.party
minus-square@TheMadnessKing@lemdro.idlinkfedilinkEnglish5•10 months agoHonestly, this is like the first time I heard WinRAR has this big security vulnerability. But I am still planning to stay on WinRAR given its easy to use UI and unlimited free trial.
minus-squarerhabarbaOPlinkfedilinkEnglish3•10 months agoIt is. Coincidentally, security was one of the reasons to uninstall 7-Zip.
minus-square@dan@upvote.aulinkfedilinkEnglish17•edit-210 months agoThere’s barely any CVEs on that page. It’s likely a security researcher did some fuzzing of the executable and found a few issues at once. Have you looked at how many vulnerabilities there’s been in things like Windows, MacOS, Chrome, etc?
minus-squarerhabarbaOPlinkfedilinkEnglish3•10 months agoI have. The point is that there is no software without vulnerabilities.
minus-square@dan@upvote.aulinkfedilinkEnglish12•10 months ago The point is that there is no software without vulnerabilities. Definitely true, but that conflicts with this: Coincidentally, security was one of the reasons to uninstall 7-Zip. If you uninstalled software because of security, you wouldn’t have any software left :)
minus-squarerhabarbaOPlinkfedilinkEnglish2•10 months agoAlso true. I was probably too impatient when I bought a WinRAR license over night. But now I have it and I use it. :-)
minus-squarerhabarbaOPlinkfedilinkEnglish3•10 months agoI even own legitimate Total Commander and mIRC licenses!
minus-square@dan@upvote.aulinkfedilinkEnglish8•10 months agoI’m sure they’re still celebrating someone purchasing a license :)
minus-squaremorry040linkfedilink9•10 months agoThe number of reported issues seems to be about the same with WinRAR: https://www.cvedetails.com/vulnerability-list/vendor_id-1914/product_id-3768/Rarlab-Winrar.html
Is security not a merit?
Honestly, this is like the first time I heard WinRAR has this big security vulnerability. But I am still planning to stay on WinRAR given its easy to use UI and unlimited free trial.
It is. Coincidentally, security was one of the reasons to uninstall 7-Zip.
There’s barely any CVEs on that page. It’s likely a security researcher did some fuzzing of the executable and found a few issues at once.
Have you looked at how many vulnerabilities there’s been in things like Windows, MacOS, Chrome, etc?
I have. The point is that there is no software without vulnerabilities.
Definitely true, but that conflicts with this:
If you uninstalled software because of security, you wouldn’t have any software left :)
Also true. I was probably too impatient when I bought a WinRAR license over night. But now I have it and I use it. :-)
Y-you paid for WinRAR?
I even own legitimate Total Commander and mIRC licenses!
Wow, a real unicorn! 🦄
I’m sure they’re still celebrating someone purchasing a license :)
The number of reported issues seems to be about the same with WinRAR: https://www.cvedetails.com/vulnerability-list/vendor_id-1914/product_id-3768/Rarlab-Winrar.html