Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-13-2006, 05:22 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 295
Trojan.Radropper Exploits WinRAR Vulnerability

Trojan.Radropper Exploits WinRAR Vulnerability
<p>Recently, we have seen a trend in Trojan horse programs exploiting popular desktop applications. The applications that have been exploited have included Microsoft Word, Excel, Powerpoint, and JustSystem's Ichitaro. Now, we have uncovered a Trojan horse exploiting a vulnerability in WinRar—software which may not be quite as well known as those examples I have just mentioned.</p>

<p>Symantec Security Response has confirmed that <a href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-101015-1014-99">Trojan.Radropper</a> exploits the <a href="http://www.securityfocus.com/bid/19043/info">RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability</a>. This vulnerability was first made public in July of this year and has subsequently been fixed. The current version of WinRAR (version 3.61) does not contain this vulnerability.</p>

<p>The attack was email based and was executed when an email with a RAR archive attachment was sent to a user. Once the archive was opened, the RAR file would drop a file, which is detected as Backdoor.Trojan, onto the user's computer.</p>

<p>This threat is considered a very low risk at this time, due to the fact that it was used in a targeted attack. Additionally, the vulnerability exploited here is not new and a patch is already available. However, if you are using WinRAR, I fully advise you to patch the software as soon as possible.</p>
http://www.symantec.com/enterprise/security_response/weblog/2006/10/trojanradropper_exploits_winra.html
http://www.symantec.com/enterprise/security_response/weblog/2006/10/trojanradropper_exploits_winra.html
Tue, 10 Oct 2006 17:56:15 -0800
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump



    All times are GMT -5. The time now is 11:23 AM.


    Firefox 2