[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


Janitor acceptance emails will be sent out over the coming weeks. Make sure to check your spam folder!


[Advertise on 4chan]


File: 1760928606442377.png (1 KB, 110x63)
1 KB PNG
DO NOT INSTALL 7-Zip 26.02

There is a massive push for people to update 7-Zip right now due to a potential RCE CVE. That CVE was fixed in version 26.01
Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for it.

This is very likely a coordinated attack to get as many people as possible using a compromised version of 7-Zip.
>>
>>109335347
I don't remember the last time i updated it.
>>
>>109335370
You should definitely update to 26.01.
There are several known exploits
>>
>>109335347
too late, they got me
>>
>>109335347
Exploit what? It runs locally on my PC without connecting to the Internet. Is this something that only affects malicious zips?
>>
Never go full schizo
>>
>>109335393
zip this brodie *unzips*
>>
>>109335393
Yes, the RCE requires a maliciously created file to be executed locally.
However that is a lot easier since the file will just behave like a normal file and you will never notice it.
>>
>>109335347
It's a little late to warn us, my package manager updated it a month ago.
>>
>>109335427
>using packet managers on windows with no chain of trust whatsoever
anon...
>>
Where is the proof retard? Goddamn who let these retard codelets in
>>
File: 1765834725854592.png (8 KB, 1103x133)
8 KB PNG
>>109335347
I've extracted like a hundred since june and posted multiple .7z archives on forums how fucked am I and everyone who unzips my posts?
>>
>>109335347
What is the point of 7-Zip / WinRAR when Windows does it by default since 8.1? Like, genuine question bros.
>>
>>109335347
uhhh I just updooted today
>>
>>109335466
how does winshit handle multi volume encrypted 7zip archives?
>>
>>109335466
It handles .7z and .tar and all the other autistic Linux compression formats
>>
>>109335347
Imagine using Microslop Gaydows or Troonix
>>
>>109335347
Nothingburger schizo babble
>>
>>109335347
>WITHOUT A CHANGELOG
just diff the source tarballs ezpz
>>
>Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for it.
But this has been the case before. I think he just pushes out updates to package managers first and does the release notes after.
>>
>>109335543
source deez tarballs
>>
>>109335347
Thanks, updooting now.
>>
>>109335347
ACHTUNG
they actually knew we would be suspicious of 26.02, make people skip it, and install compromised 26.03.
DO NOT INSTALL 7-Zip 26.03
>>
>>109335347
>>109335544
Wrong:
https://github.com/ip7z/7zip/commits/main/
>>
send me xmr guys i'll keep it safe
>>
>>109335466
>Windows does it by default since 8.1
Does it also do AES-encrypted passworded archives?
>>
>>109335611
It does NSA-encrypted archives
>>
File: 1754527676294250.jpg (51 KB, 673x720)
51 KB JPG
>ERROR Couldn't remove '~\scoop\apps\7zip\26.02'; it may be in use.
>>
You mean this?
https://www.7-zip.org/download.html
>>
nobody updates this crap
>>
File: 1777043613120092.jpg (41 KB, 396x382)
41 KB JPG
>>109335347
You having a mental health episode, OP?
>>
>>109335347
>WITHOUT A CHANGELOG
https://sourceforge.net/p/sevenzip/discussion/45797/thread/b8d64839d0/
>or the available source code for it
you sound indian.
https://github.com/ip7z/7zip/releases/download/26.02/7z2602-src.7z
>>109335445
7zip releases aren't signed so no matter what platform you are on or how many signatures are eventually attached to your package there is no chain of trust other than the HTTPS certificate on 7-zip.org.
>>109335466
Windows natively uses bsdtar for 7z which is extremely slow and cannot create .7z files.
>>
guys i my 7th zip extracted mustard gas
>>
>>109335944
open your mouth fast
>>
>>109335895
>What's new in 7-Zip 26.02:
>Some bugs and vulnerabilities were fixed.
That's not a changelog, retard
>>
>>109335972
The diff is the changelog, jeetman
>>
>>109335347
I havent update 7zip, winzip or any archiving program in decades and I'm doing fine
>>
>>109335972
yes it is
>>
>>109336076
good thing u dont pirate lmao ud get FUKKED
>>
>>109336240
I do pirate vydia, but only from trusted sources like my tranny fitgirlrepack
and for software .. well nothing good comes out anymore.
>>
File: monmyi.png (657 KB, 941x714)
657 KB PNG
>>109335406
>>
File: logo-winrar.png (6 KB, 288x66)
6 KB PNG
>>109335347
not my problem
>>
No worries here. Ubuntu ks stil on version 23.01 and plenty exploitable.
>>
my personal data is already in every phishing dump on the dark web, the value must be effectively zero by now
>>
abuse me when this gets fixed so I can upd8, icba to care about it
>>
>>109335370
>I don't remember the last time i updated it.
Based
>>
Inchecked the diff and it looks like 26.02 has significant basic security hardening. It would be more stupid to not update unless you have good reason.
>>
WinRAR does not have this problem. Freetards lose again.
>>
>>109335347
meds
>>
>>109335347
[citation needed]
>>
>>109335413
Look up what the first letter of RCE means.
Opening a malicious local file is not RCE, by definition.
>>
>>109336951
(nta)
the security theater tards can always claim that the line between local and remote is murky, since not only direct network FSes exist (nfs, samba, ..etc). but also there is the fact that fuse can wrap any network application protocol.
actually, i'm surprised they haven't been doing just that.
this actually brings us to the fact that local/remote were never good enough descriptors anyway. new categorization, with perhaps "attacker-initiated" and "user-initiated" as super categories is needed.
we already have jargon like "zero-click exploits" used, but it's too narrow-scoped.
>>
>>109335347
I just checked, im on 17.1 beta. not
sure why i would ever update.
>>
File: 1783453902333562.jpg (156 KB, 1021x1021)
156 KB JPG
>>109335347
does this affect Linux too?
>>
File: file.png (9 KB, 262x299)
9 KB PNG
>>109335347
lmfao i installed it today in my fresh windows 10
i'm back to linux
>>
File: schizo.jpg (180 KB, 960x900)
180 KB JPG
>>109335402
t. psychopath
>>
peazip enjoyer here
>>
>>109335466
zip isnt as good for compression as rar or 7z
>>
>>109335347
>or the available source code for it.
I only install software via my distribution package manager and they only package things they build themselves so if there's no source code then there's no way for me to install it.

I can't imagine doing things any other way, you probably get malware all the time.
>>
>>109335581
addy? i got a bunch and im about to die of aids in the next 10-20 mins
>>
how do you even install something without dev-signed source code?
t. gentoo user
>>
>>109337658
Air gapped device then Wireshark
>>
>>109335370
Catposter is the best poster
>>
>>109335944
uh oh, stinky
>>
>>109335347
I wish someone would hack me. my documents folder is literally just 230GB of the same photo of my penis I took with my cell phone and a bunch of pdf files explaining how to make Methamphetamine
>>
>>109335347
>download program once
>get exposed to hacking risk only once
>updoot every 14 days
>have a chance to get hacked every 14 days
>>
>>109337861
Thanks for the hearty kek. Unfortunately I'm in bed and about to sleep. I hope that doesn't affect my dreams. Lmao
>>
It might end like this: >>109331258.
>>
>>109335347
It's been almost a month since release, nothing is coming up on AVs or sandbox analysis programs. The source code IS AVAILABLE.
Are you actually accusing the author of LIKELY making malware?
>>
>>109335347
i'm glad using such version 7z1900-x64
>>
>>109335347
>Version 26.02 is a version WITHOUT A CHANGELOG or the available source code for it
Explain how 7zip-zs exists then
>>
>>109335347
This is what you get for using redditroons program
Winrar is perfectly fine to use
>>
>>109336951
the question is, how tfk 7zip has default port open? remote mean, there's an open port. why tfk 7zip need it?
>>
>>109338092
NSAkey ingestion
>>
>>109338092
If you sincerely seek an answer, it looks like 7 zip works over network shares just like explorer, or any other file manager,

If you fully encrypt a zip file, it can then only be accessible through the 7 zip file manager, at least on Windows.
>>
>>109335347
>devs name is Igor
I stopped trusting this thing a long time ago desu.
>>
File: IMG_1097.jpg (285 KB, 1351x1340)
285 KB JPG
>>109335347
>26.02 is a version WITHOUT A CHANGELOG or the available source code for it.
huh?
>>
>>109335347
Zip this
*unzips bandizip*
>>
>>109338113
i don't really i understand your statement. if it work through network shares, then the problem is network share (smb) not the 7zip. curious is it a backdoor or what?
>>
>>109335370
it do be like THAT
>>
File: 376578454756.png (21 KB, 612x616)
21 KB PNG
Don't care. I use the superior software, PeaZip.
>>
>>109335347
Thanks, but I trust the developer more than some retard online.
>>
>>109335466
>doesn't support password protected .7z archives
>support for creating archives is extremely limited, no options for splits or compression level or anything like that
>decompression is extremely slow and will often just shit itself for no reason and take hours for stuff that 7z decompresses in seconds
it's like you never even used the feature, it's common knowledge that the built in support for archives on windows is pretty much unusable
>>
I'm a NanaZip chad bro
>>
File: file.png (8 KB, 452x318)
8 KB PNG
thanks for reminder I am now up to date
>>
>>109338434
thanks.

it's heap overflow. not RCE. fcking retarded.
of course it's local, and cause a remote backdoor.
>>
No wonder why it's called WINrar.
>>
>>109338434
They fixed a ton of vulnerabilities. I think the dev did not want to admit to just how many vulnerabilities existed.
>>
>>109337885
more like
>download program once
>have greater risk of getting hacked with each passing day and each discovered vulnerability
>updoot every 14 days
>have a low chance to get hacked with fresh exploits form the last 14 days
>>
>>109338492
>>109335611
>>109335489
the only reason for password protected zips is for pedophiles to protect child pornography.
>>
>>109337927
Buy an ad.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.