Showing posts with label Packing & Unpacking Files. Show all posts
Showing posts with label Packing & Unpacking Files. Show all posts

Tuesday, 13 October 2015

NCSC Attracts Warning For WinRAR Leak



The National Cyber ​​Security Center (NCSC), the government has decided to withdraw an alert for a vulnerability in the popular archiving program WinRAR, since the vulnerability is in Windows but not in WinRAR and there is last year's patched.

In late September demonstrated a researcher how he could attack via a malicious SFX archives using Windows. WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. By letting users open a malicious SFX archive an attacker could execute arbitrary code with the rights of the logged in user, says the researcher.

Then the NCSC came with a warning. In it, the vulnerability was described as "average". However, the attack of the researcher appears to work only if the computer has a security update for Windows mist that was released by Microsoft last November. Something RARLAB, the developer of WinRAR, most recently through the website announced. Because of this additional information decided anti-malware company Malwarebytes too a blog posting about the alleged vulnerability remove and now has the NCSC's security advisory today revoked.

Friday, 9 October 2015

Malwarebytes Removes Blog Posting About WinRAR Leak


Malwarebytes has removed a blog posting about a vulnerability in WinRAR, because the information posted was inaccurate. The anti-malware company then makes excuses to WinRAR. Recently gave an investigator a demonstration where he could take over via a malicious SFX archives computers.

WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. SFX archives are basically just exe files and consist of the packed file and the unpack module WinRAR.

The National Cyber ​​Security Center (NCSC), the government decided because of the vulnerability a warning to issue.Contrary to some media reports, the problem not only for users of WinRAR, but to all Windows users who receive a malicious SFX archives. According RARLAB, developer of WinRAR, users need to open exe files, be it a SFX archive or not, always be careful.

Malwarebytes is now proposing that the information in the blog posting was not well controlled. Which has subsequently proven to be wrong. The demonstrated attack was in fact not directed against WinRAR users. In addition, users must double-click the malware before it is activated. It also appears that the vulnerability that is used in the attack in November last year was patched by Microsoft. Malwarebytes gave new excuses to RARLAB and agreed to the blog posting about the vulnerability remove. However, the posting is still in the cache of Google to find.

Wednesday, 30 September 2015

Researcher Makes Malicious SFX Archives Using WinRAR



Through a leak in the popular archiving program WinRAR it is possible to create a malicious SFX archive that random Internet users to attack, so warns the National Cyber ​​Security Center (NCSC), but according to the developers of the software it is a feature .

WinRAR is a very popular program for packing and unpacking files. Besides the standard RAR archive, the software can also make a Self Able Extract (SFX) archives. In this case the archive file is unpacked automatically when the user opens the file, regardless of whether they have installed WinRAR or not. By letting users open a malicious SFX archive an attacker could execute arbitrary code with the rights of the logged in user.

The vulnerability is caused by an attacker to create an SFX archive malicious HTML code in the "Text to display in SFX window" option can add. This allows an attacker to specify code to be executed automatically when you open the SFX file, such as downloading and executing an .exe file. According to the German Heise, it is a feature of the SFX-documented option. The developers of WinRAR could therefore see no reason to prevent the downloading of executable files via the web.