Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

19-years-old WinRAR vulnerability leads to over 100 malware exploits (Update Now!)
SlashGear ^ | Mar 16, 2019 | Adam Westlake

Posted on 03/18/2019 6:04:06 AM PDT by dayglored

After being a staple on PCs for so many years, last month it was discovered that WinRAR, software used to open .zip archive files, has been vulnerable for the last 19 years to a bug that’s easily exploited by hackers and malware distributors. Fortunately, the software has been patched with the recent release of version 5.70, but after being unchecked for so long and installed by so many people, a new wave of malware is taking advantage.

Check Point, the security researchers that revealed the WinRAR bug, explain that the software is exploited by giving malicious files a RAR extension, so that when opened they can automatically extract malware programs. These programs are installed in a PC’s startup folder, allowing them to start running anytime the computer is turned on, all without the user’s knowledge.

Once the bug was disclosed, however, hacker groups really began using it to their advantage, with various nations becoming the target of state-backed cyber-espionage campaigns attempting to collect intelligence. The latest comes from McAfee, the software security firm, which notes that it has identified over 100 unique exploits that use the WinRAR bug, most of them targeting the US.

Malware distributors are well aware of WinRAR’s prevalence among those who prefer to illegally download their media, as McAfee notes that one of the more popular exploits targets victims with a bootleg copy of Ariana Grande’s latest album, Thank U, Next.

The WinRAR software isn’t nearly as popular as it was years ago, but since it’s racked up over 500 million users in almost 20 years, there’s no way to know how many have been affected by the bug. The other big problem is that while version 5.70 was released in late January, it must be manually downloaded and installed from the website, leaving most users unaware of the critical update.


TOPICS: Business/Economy; Computers/Internet; Hobbies
KEYWORDS: exploit; malware; windowspinglist; winrar
Navigation: use the links below to view more comments.
first previous 1-2021-26 last
To: Bob434

lol

With that malware slowing things down it will take days to download one naughty picture!!

:)


21 posted on 03/18/2019 11:11:59 AM PDT by dp0622 (The Left should know if.. Trump is kicked out of office, it is WAR!)
[ Post Reply | Private Reply | To 19 | View Replies]

To: dayglored
I like PeaZip free archiver utility, open extract RAR TAR ZIP files www.peazip.org/
22 posted on 03/18/2019 12:40:35 PM PDT by daniel1212 (Trust the risen Lord Jesus to save you as a damned and destitute sinner + be baptized + follow Him)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

This is Skynet’s doing, for sure!


23 posted on 03/18/2019 1:02:48 PM PDT by Tolerance Sucks Rocks (Modern feminism: ALL MEN BAD!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Speaking of “malware”, it seems that every website these days has a message letting us know that the site uses cookies, and it asks us if we’re OK with that. I’m always saying “yes”, but this is a bit annoying to me. Is this message something required by one of those federal laws that is completely unnecessary for computer users with an IQ above room temperature?


24 posted on 03/18/2019 1:14:30 PM PDT by Tolerance Sucks Rocks (Modern feminism: ALL MEN BAD!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Tolerance Sucks Rocks
Speaking of “malware”, it seems that every website these days has a message letting us know that the site uses cookies, and it asks us if we’re OK with that. I’m always saying “yes”, but this is a bit annoying to me. Is this message something required by one of those federal laws that is completely unnecessary for computer users with an IQ above room temperature?
I haven’t tried this yet, but it might help:

I don’t care about cookies

25 posted on 03/19/2019 3:05:45 AM PDT by cartan
[ Post Reply | Private Reply | To 24 | View Replies]

To: dayglored

Dang! I like winrar.


26 posted on 03/19/2019 8:26:04 PM PDT by dennisw
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-26 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson