LibreTechni.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
sanitation@lemmy.today to PC Master Race@lemmy.worldEnglish · 2 days ago

Russian Hackers Are Still Exploiting a WinRAR Vulnerability, Here's How to Protect Yourself

respawnfirst.com

external-link
message-square
22
fedilink
72
external-link

Russian Hackers Are Still Exploiting a WinRAR Vulnerability, Here's How to Protect Yourself

respawnfirst.com

sanitation@lemmy.today to PC Master Race@lemmy.worldEnglish · 2 days ago
message-square
22
fedilink
alert-triangle
You must log in or register to comment.
  • Phoenixz@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    15 hours ago

    Here is how you protect yourself

    Don’t use tar

    Don’t use windows

    Done.

  • /home/pineapplelover@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    15 hours ago

    Bruh we use winrar at work

    Edit: it wasn’t my decision

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    53
    ·
    2 days ago

    Tldr. Update WinRAR.

    Better option, uninstall WinRAR and use something more sensible like 7zip.

    • Phoenixz@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      15 hours ago

      Better option: move to Linux, also dump rar

    • P03 Locke@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      1 day ago

      Who the fuck still uses WinRAR?

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Orgs who haven’t updated their processes in 20 years and still have a valid license.

        • Tiral@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          20 hours ago

          License? I thought the point was to see how high the number went every time you opened it.

          • slazer2au@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            19 hours ago

            Until you are a business and you get reamed by legal for using unlicensed software putting the business at legal risk.

    • cRazi_man@europe.pub
      link
      fedilink
      English
      arrow-up
      16
      ·
      2 days ago

      I’m more of a PeaZip person myself.

      • kn33@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        I like Nanazip

        • cRazi_man@europe.pub
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 days ago

          Full list of options…before this turns into a long list of options: https://alternativeto.net/software/winrar/?license=opensource

          • certified_expert@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 day ago

            Laughs in tar.gz

    • pulsewidth@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      edit-2
      2 days ago

      I’ll just uh… Leave these here.

      https://www.tomshardware.com/tech-industry/cyber-security/wide-ranging-7-zip-vulnerability-with-8-8-cve-rating-allows-for-code-execution-hundreds-of-millions-of-machines-potentially-at-risk

      https://cybersecuritynews.com/7-zip-rce-vulnerability-exploited/ (another similar CVE from late last year)

      I use 7-zip myself, and have for over a decade, but it too has like… A major CVE around once every six months - worse than WinRARs record actually.

      Its no silver bullet.

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        Not a silver bullet but the functionality of 7zip is far greater then WinRAR.

  • certified_expert@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    Me laughing in tar

    • MonkderVierte@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 hours ago

      Dumb and inefficient but simple enough to not care about your newfangled “security exploits”.

      • certified_expert@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        15 hours ago

        Do you have any foundation for your claim?

        • tar paired with gzip or xz it is quite comparable in compression ratios. xz can be actually better than rar.
        • tar preserves file permissions.
        • tar lets you just pack files together with no compression at near instant speed
        • you can pipe it

        Dumb is a feature: do one thing and do it well. Inefficient? BS.

        Here a qick comparison

        • MonkderVierte@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          15 hours ago

          tar has no index for quick lookup, tar extracts in quadratic time, stuff like that. I mean, even zip can extract a 1 MB file in a second from a 5 GB archive, tar needs to extract the whole thing.
          No “magic byte” either, making life hard for mime-tooling.

          To be fair, it was made for tape backups.

          • tar lets you just pack files together with no compression at near instant speed

          cat does so too. Add a index with metadata and a separator bit between the files and you almost have a tar but better in some areas.

          • certified_expert@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 hours ago

            “tar extracts in quadratic time, stuff like that”. Is that what your favorite clanker told you? If that’s the case, why is uncompressed tar almost instant in practice when others take many seconds? Or compressed tars in the same time neighborhood than any other tool?

            Who does “quick lookups” in an arcived file? At most a content listing and then parse/grep whatever you want.

            About cat: Sure bud, but go and reconstruct a folder after you cated it.

  • betterdeadthanreddit@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 days ago

    Could have afforded more secure code if anyone had bothered to buy WinRAR instead of clicking through the nag screen every time.

    • wltr@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      Why use it in the first place? To me that’s some ‘hi from 2000s’ kind of thing.

      • myrmidex@belgae.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 days ago

        Indeed, I also got a lot of “are you from the past?” vibes

PC Master Race@lemmy.world

pcmasterrace@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !pcmasterrace@lemmy.world

A community for PC Master Race.

Rules:

  1. No bigotry: Including racism, sexism, homophobia, transphobia, or xenophobia. Code of Conduct.
  2. Be respectful. Everyone should feel welcome here.
  3. No NSFW content.
  4. No Ads / Spamming.
  5. Be thoughtful and helpful: especially when new beginners have questions.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 340 users / day
  • 1.56K users / week
  • 4.04K users / month
  • 5.54K users / 6 months
  • 1 local subscriber
  • 21.4K subscribers
  • 201 Posts
  • 1.18K Comments
  • Modlog
  • mods:
  • _MoveSwiftly@lemmy.world
  • BigFig@lemmy.world
  • IowaMan@lemmy.world
  • Starfer@lemmy.world
  • The_Vampire@lemmy.world
  • Fudgeknuckles98@lemmy.world
  • CatZoomies@lemmy.world
  • Xeon@lemmy.ml
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org