Cult I Mean Group
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
rhabarba@feddit.de to Technology@beehaw.orgEnglish · 2 years ago

WinRAR zero-day exploited since April to hack trading accounts

www.bleepingcomputer.com

external-link
message-square
22
fedilink
108
external-link

WinRAR zero-day exploited since April to hack trading accounts

www.bleepingcomputer.com

rhabarba@feddit.de to Technology@beehaw.orgEnglish · 2 years ago
message-square
22
fedilink
  • bug@lemmy.one
    link
    fedilink
    English
    arrow-up
    37
    ·
    2 years ago

    Is security not a merit?

    • TheMadnessKing@lemdro.id
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 years ago

      Honestly, this is like the first time I heard WinRAR has this big security vulnerability. But I am still planning to stay on WinRAR given its easy to use UI and unlimited free trial.

    • rhabarba@feddit.deOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 years ago

      It is. Coincidentally, security was one of the reasons to uninstall 7-Zip.

      • dan@upvote.au
        link
        fedilink
        English
        arrow-up
        17
        ·
        edit-2
        2 years ago

        There’s barely any CVEs on that page. It’s likely a security researcher did some fuzzing of the executable and found a few issues at once.

        Have you looked at how many vulnerabilities there’s been in things like Windows, MacOS, Chrome, etc?

        • rhabarba@feddit.deOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 years ago

          I have. The point is that there is no software without vulnerabilities.

          • dan@upvote.au
            link
            fedilink
            English
            arrow-up
            12
            ·
            2 years ago

            The point is that there is no software without vulnerabilities.

            Definitely true, but that conflicts with this:

            Coincidentally, security was one of the reasons to uninstall 7-Zip.

            If you uninstalled software because of security, you wouldn’t have any software left :)

            • rhabarba@feddit.deOP
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 years ago

              Also true. I was probably too impatient when I bought a WinRAR license over night. But now I have it and I use it. :-)

              • averyminya@beehaw.org
                link
                fedilink
                arrow-up
                9
                ·
                2 years ago

                Y-you paid for WinRAR?

                • rhabarba@feddit.deOP
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  2 years ago

                  I even own legitimate Total Commander and mIRC licenses!

                  • snowbell@beehaw.org
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    ·
                    2 years ago

                    Wow, a real unicorn! 🦄

              • dan@upvote.au
                link
                fedilink
                English
                arrow-up
                8
                ·
                2 years ago

                I’m sure they’re still celebrating someone purchasing a license :)

      • morry040@kbin.social
        link
        fedilink
        arrow-up
        9
        ·
        2 years ago

        The number of reported issues seems to be about the same with WinRAR: https://www.cvedetails.com/vulnerability-list/vendor_id-1914/product_id-3768/Rarlab-Winrar.html

Technology@beehaw.org

technology@beehaw.org

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@beehaw.org

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 117 users / day
  • 1.23K users / week
  • 2.88K users / month
  • 7.51K users / 6 months
  • 2 local subscribers
  • 38.6K subscribers
  • 3.68K Posts
  • 58.7K Comments
  • Modlog
  • mods:
  • alyaza [they/she]@beehaw.org
  • TheRtRevKaiser@beehaw.org
  • gyrfalcon@beehaw.org
  • rs5th@beehaw.org
  • coldredlight@beehaw.org
  • Leigh@beehaw.org
  • TheRtRevKaiser@kbin.social
  • Chris Remington@beehaw.org
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org