lemmy.onlylans.io
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
rhabarba@feddit.de to Technology@beehaw.orgEnglish · 3 年前

WinRAR zero-day exploited since April to hack trading accounts

www.bleepingcomputer.com

external-link
message-square
21
fedilink
108
external-link

WinRAR zero-day exploited since April to hack trading accounts

www.bleepingcomputer.com

rhabarba@feddit.de to Technology@beehaw.orgEnglish · 3 年前
message-square
21
fedilink
  • bug@lemmy.one
    link
    fedilink
    English
    arrow-up
    37
    ·
    3 年前

    deleted by creator

    • TheMadnessKing@lemdro.id
      link
      fedilink
      English
      arrow-up
      5
      ·
      3 年前

      Honestly, this is like the first time I heard WinRAR has this big security vulnerability. But I am still planning to stay on WinRAR given its easy to use UI and unlimited free trial.

    • rhabarba@feddit.deOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 年前

      It is. Coincidentally, security was one of the reasons to uninstall 7-Zip.

      • dan@upvote.au
        link
        fedilink
        English
        arrow-up
        17
        ·
        edit-2
        3 年前

        There’s barely any CVEs on that page. It’s likely a security researcher did some fuzzing of the executable and found a few issues at once.

        Have you looked at how many vulnerabilities there’s been in things like Windows, MacOS, Chrome, etc?

        • rhabarba@feddit.deOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          3 年前

          I have. The point is that there is no software without vulnerabilities.

          • dan@upvote.au
            link
            fedilink
            English
            arrow-up
            12
            ·
            3 年前

            The point is that there is no software without vulnerabilities.

            Definitely true, but that conflicts with this:

            Coincidentally, security was one of the reasons to uninstall 7-Zip.

            If you uninstalled software because of security, you wouldn’t have any software left :)

            • rhabarba@feddit.deOP
              link
              fedilink
              English
              arrow-up
              2
              ·
              3 年前

              Also true. I was probably too impatient when I bought a WinRAR license over night. But now I have it and I use it. :-)

              • averyminya@beehaw.org
                link
                fedilink
                arrow-up
                9
                ·
                3 年前

                Y-you paid for WinRAR?

                • rhabarba@feddit.deOP
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  3 年前

                  I even own legitimate Total Commander and mIRC licenses!

                  • snowbell@beehaw.org
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    3 年前

                    Wow, a real unicorn! 🦄

              • dan@upvote.au
                link
                fedilink
                English
                arrow-up
                8
                ·
                3 年前

                I’m sure they’re still celebrating someone purchasing a license :)

      • morry040@kbin.social
        link
        fedilink
        arrow-up
        9
        ·
        3 年前

        The number of reported issues seems to be about the same with WinRAR: https://www.cvedetails.com/vulnerability-list/vendor_id-1914/product_id-3768/Rarlab-Winrar.html

Technology@beehaw.org

technology@beehaw.org

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 437 users / day
  • 982 users / week
  • 2.43K users / month
  • 6.46K users / 6 months
  • 5 local subscribers
  • 42.6K subscribers
  • 5.25K Posts
  • 96.6K Comments
  • Modlog
  • mods:
  • alyaza [they/she]@beehaw.org
  • TheRtRevKaiser@beehaw.org
  • gyrfalcon@beehaw.org
  • rs5th@beehaw.org
  • coldredlight@beehaw.org
  • Leigh@beehaw.org
  • TheRtRevKaiser@kbin.social
  • Chris Remington@beehaw.org
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org