WinRAR zero-day exploited since April to hack trading accounts
bleepingcomputer.com
bleepingcomputer.com
Doesn't 7zip do all of this (and quite a bit more)?
It seems you only get infected if you double click a malicious rat archive then within WinRAR, double click one of the legitimate PDF or image files.
Either way, it’s a bad scenario - I just would like to know. Tks
It's also alike a zero day in the other sense that protections against the exploit haven't been developed. While in a real zero day that's because not enough time has passed for volunteers to develop protections, the case here is proprietary software can't be modified by volunteers.
Is there a good reason? It frequently feels like it's used just to make extra work for the downloader
I do an I absolutely loathe when something is compressed as 7z.
Sometimes you need to split archives Sometimes you want to open a non-standard file type with something to unpack it (.xlsx/self extracting .exe) Sometimes you've got Software Restriction Policies that prevent standard %temp% extraction installers from running and need to manually extract a package.
This is the short list
That said, RAR and 7zip compress much, much better than ZIP (faster or more).
Finally, the built-in integrity hashing that 7-zip adds to the right-click context menu in Windows is crazy useful.
So to answer your question: there are plenty of legitimate reasons to still use 7zip. I can't think of any legitimate reasons to still use WinRAR, though...
[1] - https://github.com/Parchive/par2cmdline [In need of a new maintainer]
And this for Linux https://github.com/animetosho/par2cmdline-turbo
Uploaders who just transfer scene releases without bothering to extract will of course stick to RAR, but there's a lot of content these days that isn't from scene groups.
which are?..
If you need the interop then you can't beat ZIP
If you need a built-in recovery record (and find a working decompressing program 10-20 years later) then you can't beat RAR
If your corporate is insane and forbids 7z because it's FOSS/made by Russian then you can't beat RAR
Which are those 'better options'?
Is the algorithm itself actually available somewhere? IIRC 7zip had compatibility issues with some RAR files out there that opens up just fine with WinRAR, so I assumed they had to figure out the algo themselves.
https://www.rarlab.com/rar_add.htm
The source has the following restriction:
UnRAR source code may be used in any software to handle
RAR archives without limitations free of charge, but cannot be
used to develop RAR (WinRAR) compatible archiver and to
re-create RAR compression algorithm, which is proprietary.
Distribution of modified UnRAR source code in separate form
or as a part of other software is permitted, provided that
full text of this paragraph, starting from "UnRAR source code"
words, is included in license, or in documentation if license
is not available, and in source code comments of resulting package.Ironic, isn't 7-Zip the program where the developer has famously refused to provide download hashes or digital signatures of the release binaries?
My immediate thoughts were, "What the hell is this?" and "Why didn't they just give me an EXE?"
https://blogs.windows.com/windows-insider/2023/08/18/announc...
It's only available on the preview channel for now but it's coming.
https://github.com/libarchive/libarchive#supported-formats
edit: amended my last reply, Microsofts latest blog post says that XZ and Zstd are also supported.
Don't get me wrong, I love that they add support for more open source formats, but decompressors (especially written in C) are one of the most common sources of bugs basically everywhere. I wish they would sandbox it, but they probably won't.
The details escape me, but I live somewhere with a non-Latin script and it rars were very popular here ten-fifteen years ago for this reason.
This is just another cost of sticking to legacy formats.
I also recommend NanaZip (a fork of 7zip) instead of 7zip since it integrates better with Windows 11 context menu.
RAR is used on the internet because large files get broken up into smaller parts to get transferred and you can use RAR to determine whether your compressed fileset is legitimate or if it needs repair. That's where recovery volumes come in. If it won't unrar, then you can just add enough recovery files until it does.
WinRAR opens a .tar.gz like any other single-format archive (zip, rar, 7z) so it's much much faster, but also more intuitive.
Even though I use WinRAR, I only create ZIPs for compatibility with others. I would also stick to ZIPs if I were to use 7zip.
And because we can assume everyone in the office has 7zip, we don't have to create zips for things that go between windows and linux systems.
We are talking about the program that adds like four options to the right click menu throughout your entire system right?
The Windows zip tool failed just yesterday because some of my file names had illegal characters yet 7zip/winrar handled it no problem.
Better compression / more options
Beyond that, there's not much I need it for but every time I remove it ... I end up needed it shortly!
Also, a common gesture I use is 7zip's extensions to the right-click drag file operation. I can select an entire collection of zip files right-click drag it to a different folder and "Extract to *\" which decompresses all the files into a set of folders (under the folder you are dragging into) using the names of the zip files as the folder names (minus the extension). This is a useful and surprisingly common operation. (For instance, downloading a bunch of Bandcamp albums on a Bandcamp Friday and decompressing them all at once to a music library folder.)
WinZIP should probably have died in the 90s.
Deflate is a 16bit algorithm from '91. Which is slow and the density is low.
Zip doesn't store access rights, unlike tar. That's why tar gzip is so popular on Linux.
i personally use rar (not winrar because i am not on windows) because it also: locks created archive, tests it, and adds a recovery record so if a few bits or even bytes flip it can be recovered.
rar also has a ton of options to customize compression like splitting into multiple files (i think 7z does this too as well)
There's a more interesting question lying in there:
"Zip is built into literally everything."
From my anecdotal evidence with random Windows software, for said support, developers probably bundled 7zip in order to support compressed file formats.
Granted, in the end the fact that 7zip is bundled, or if 7zip and it's several features are exposed to you as a end-user is another story.
For ~half of the world’s population it’s literally useless.
7zip is a much more powerful tool
You can argue for your political beliefs, sure, but let's be honest and not claim that there are any security benefits.
What's more, doing security review is very hard. You can't just casually read a bit of code. You need to deeply understand the surrounding context. People who have the capability to do that aren't going around providing that service for free.
-- More reading for the curious: https://www.explainxkcd.com/wiki/index.php/2347:_Dependency
Exploring archives a-la-WinZIP has made little sense to me since (content previews however would still be helpful)
macOS unarchivers don't have that issue. Extractions always create a single item: either extract the single item in the archive or create a folder with the archives’s name before extracting.
two-files.zip creates two-files/a.txt and two-files/b.txt
one-file.zip creates a.txt
The original author Eugene Roshal (iirc) isn't.
If you don't know, this is not even the first file compression related exploit. "Zip Slip"(0) for example, is just one year old, and there are many of them out there.
[Zip Slip]: https://nvd.nist.gov/vuln/detail/CVE-2022-21675
I personally would like to see AI be able to review entire code bases and see the bigger picture because state sponsored lawful intercepts are rarely one piece of code but rather require multiple pieces of code and sometimes hardware to work in conjunction to form the back door.
The trust issues with software developed by Russians isn't that the engineers are Russian. It's that the engineers and their families are currently in Russia.
The ability of the Russian government to lean on incredibly talented developers is extremely large.
The file extension spoof fix is nice, however.