DO NOT INSTALL 7-Zip 26.02There is a massive push for people to update 7-Zip right now due to a potential RCE CVE. That CVE was fixed in version 26.01Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for it.This is very likely a coordinated attack to get as many people as possible using a compromised version of 7-Zip.
>>109335347I don't remember the last time i updated it.
>>109335370You should definitely update to 26.01.There are several known exploits
>>109335347too late, they got me
>>109335347Exploit what? It runs locally on my PC without connecting to the Internet. Is this something that only affects malicious zips?
Never go full schizo
>>109335393zip this brodie *unzips*
>>109335393Yes, the RCE requires a maliciously created file to be executed locally.However that is a lot easier since the file will just behave like a normal file and you will never notice it.
>>109335347It's a little late to warn us, my package manager updated it a month ago.
>>109335427>using packet managers on windows with no chain of trust whatsoeveranon...
Where is the proof retard? Goddamn who let these retard codelets in
>>109335347I've extracted like a hundred since june and posted multiple .7z archives on forums how fucked am I and everyone who unzips my posts?
>>109335347What is the point of 7-Zip / WinRAR when Windows does it by default since 8.1? Like, genuine question bros.
>>109335347uhhh I just updooted today
>>109335466how does winshit handle multi volume encrypted 7zip archives?
>>109335466It handles .7z and .tar and all the other autistic Linux compression formats
>>109335347Imagine using Microslop Gaydows or Troonix
>>109335347Nothingburger schizo babble
>>109335347>WITHOUT A CHANGELOGjust diff the source tarballs ezpz
>Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for it.But this has been the case before. I think he just pushes out updates to package managers first and does the release notes after.
>>109335543source deez tarballs
>>109335347Thanks, updooting now.
>>109335347ACHTUNGthey actually knew we would be suspicious of 26.02, make people skip it, and install compromised 26.03.DO NOT INSTALL 7-Zip 26.03
>>109335347>>109335544Wrong:https://github.com/ip7z/7zip/commits/main/
send me xmr guys i'll keep it safe
>>109335466>Windows does it by default since 8.1Does it also do AES-encrypted passworded archives?
>>109335611It does NSA-encrypted archives
>ERROR Couldn't remove '~\scoop\apps\7zip\26.02'; it may be in use.
You mean this?https://www.7-zip.org/download.html
nobody updates this crap
>>109335347You having a mental health episode, OP?
>>109335347>WITHOUT A CHANGELOGhttps://sourceforge.net/p/sevenzip/discussion/45797/thread/b8d64839d0/>or the available source code for ityou sound indian.https://github.com/ip7z/7zip/releases/download/26.02/7z2602-src.7z>>1093354457zip releases aren't signed so no matter what platform you are on or how many signatures are eventually attached to your package there is no chain of trust other than the HTTPS certificate on 7-zip.org.>>109335466Windows natively uses bsdtar for 7z which is extremely slow and cannot create .7z files.
guys i my 7th zip extracted mustard gas
>>109335944open your mouth fast
>>109335895>What's new in 7-Zip 26.02:>Some bugs and vulnerabilities were fixed.That's not a changelog, retard
>>109335972The diff is the changelog, jeetman
>>109335347I havent update 7zip, winzip or any archiving program in decades and I'm doing fine
>>109335972yes it is
>>109336076good thing u dont pirate lmao ud get FUKKED
>>109336240I do pirate vydia, but only from trusted sources like my tranny fitgirlrepackand for software .. well nothing good comes out anymore.
>>109335406
>>109335347not my problem
No worries here. Ubuntu ks stil on version 23.01 and plenty exploitable.
my personal data is already in every phishing dump on the dark web, the value must be effectively zero by now
abuse me when this gets fixed so I can upd8, icba to care about it
>>109335370>I don't remember the last time i updated it.Based
Inchecked the diff and it looks like 26.02 has significant basic security hardening. It would be more stupid to not update unless you have good reason.
WinRAR does not have this problem. Freetards lose again.
>>109335347meds
>>109335347[citation needed]
>>109335413Look up what the first letter of RCE means.Opening a malicious local file is not RCE, by definition.
>>109336951(nta)the security theater tards can always claim that the line between local and remote is murky, since not only direct network FSes exist (nfs, samba, ..etc). but also there is the fact that fuse can wrap any network application protocol.actually, i'm surprised they haven't been doing just that.this actually brings us to the fact that local/remote were never good enough descriptors anyway. new categorization, with perhaps "attacker-initiated" and "user-initiated" as super categories is needed.we already have jargon like "zero-click exploits" used, but it's too narrow-scoped.
>>109335347I just checked, im on 17.1 beta. notsure why i would ever update.
>>109335347does this affect Linux too?
>>109335347lmfao i installed it today in my fresh windows 10i'm back to linux
>>109335402t. psychopath
peazip enjoyer here
>>109335466zip isnt as good for compression as rar or 7z
>>109335347>or the available source code for it.I only install software via my distribution package manager and they only package things they build themselves so if there's no source code then there's no way for me to install it.I can't imagine doing things any other way, you probably get malware all the time.
>>109335581addy? i got a bunch and im about to die of aids in the next 10-20 mins
how do you even install something without dev-signed source code?t. gentoo user
>>109337658Air gapped device then Wireshark
>>109335370Catposter is the best poster
>>109335944uh oh, stinky
>>109335347I wish someone would hack me. my documents folder is literally just 230GB of the same photo of my penis I took with my cell phone and a bunch of pdf files explaining how to make Methamphetamine
>>109335347>download program once>get exposed to hacking risk only once>updoot every 14 days>have a chance to get hacked every 14 days
>>109337861Thanks for the hearty kek. Unfortunately I'm in bed and about to sleep. I hope that doesn't affect my dreams. Lmao
It might end like this: >>109331258.
>>109335347It's been almost a month since release, nothing is coming up on AVs or sandbox analysis programs. The source code IS AVAILABLE.Are you actually accusing the author of LIKELY making malware?
>>109335347i'm glad using such version 7z1900-x64
>>109335347>Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for itExplain how 7zip-zs exists then
>>109335347This is what you get for using redditroons programWinrar is perfectly fine to use
>>109336951the question is, how tfk 7zip has default port open? remote mean, there's an open port. why tfk 7zip need it?
>>109338092NSAkey ingestion
>>109338092If you sincerely seek an answer, it looks like 7 zip works over network shares just like explorer, or any other file manager,If you fully encrypt a zip file, it can then only be accessible through the 7 zip file manager, at least on Windows.
>>109335347>devs name is IgorI stopped trusting this thing a long time ago desu.
>>109335347>26.02 is a version WITHOUT A CHANGELOG or the available source code for it.huh?
>>109335347Zip this*unzips bandizip*
>>109338113i don't really i understand your statement. if it work through network shares, then the problem is network share (smb) not the 7zip. curious is it a backdoor or what?
>>109335370it do be like THAT
Don't care. I use the superior software, PeaZip.
>>109335347Thanks, but I trust the developer more than some retard online.
>>109335466>doesn't support password protected .7z archives>support for creating archives is extremely limited, no options for splits or compression level or anything like that>decompression is extremely slow and will often just shit itself for no reason and take hours for stuff that 7z decompresses in secondsit's like you never even used the feature, it's common knowledge that the built in support for archives on windows is pretty much unusable
I'm a NanaZip chad bro
thanks for reminder I am now up to date
>>109338434thanks.it's heap overflow. not RCE. fcking retarded.of course it's local, and cause a remote backdoor.
No wonder why it's called WINrar.
>>109338434They fixed a ton of vulnerabilities. I think the dev did not want to admit to just how many vulnerabilities existed.
>>109337885more like>download program once>have greater risk of getting hacked with each passing day and each discovered vulnerability>updoot every 14 days>have a low chance to get hacked with fresh exploits form the last 14 days