"A malicious archive could contain files with crafted relative paths tricking WinRAR into "silently" extracting those to sensitive locations like system directories and auto-run or startup folders.
Although the programs will run with user-level access rather than administrative or SYSTEM rights, they can still steal sensitive data like browser cookies and saved passwords, install persistence mechanisms, or provide remote access for further lateral movement."
bleepingcomputer.com/news/secu…
just another part in the series of "why you should sandbox application that interacts with files from the internet"
:hoshino_zzz: likes this.
oAnth
in reply to Part_of You • • •Part_of You
in reply to Part_of You • • •oAnth
in reply to Part_of You • • •Je ne me rappelle pas avoir entendu un quelconque démenti, du moins dans les médias occidentaux.
Il semble que les Iraniens l'avaient intentionnellement dissimulé : trompe le trompeur avec ses propres méthodes.