
{"id":6621,"date":"2019-02-23T03:59:14","date_gmt":"2019-02-23T03:59:14","guid":{"rendered":"http:\/\/tapchicntt.com\/?p=6621"},"modified":"2023-08-18T08:11:19","modified_gmt":"2023-08-18T01:11:19","slug":"phat-hien-loi-bao-mat-nghiem-trong-tren-winrar-co-the-anh-huong-toi-500-trieu-nguoi-dung","status":"publish","type":"post","link":"https:\/\/tapchicntt.com\/phat-hien-loi-bao-mat-nghiem-trong-tren-winrar-co-the-anh-huong-toi-500-trieu-nguoi-dung\/","title":{"rendered":"Ph\u00e1t hi\u1ec7n l\u1ed7i b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng tr\u00ean WinRAR c\u00f3 th\u1ec3 \u1ea3nh h\u01b0\u1edfng t\u1edbi 500 tri\u1ec7u ng\u01b0\u1eddi d\u00f9ng"},"content":{"rendered":"\n<p>L\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng n\u00e0y c\u00f3 th\u1ec3 khi\u1ebfn m\u00e1y t\u00ednh c\u1ee7a n\u1eeda t\u1ef7 ng\u01b0\u1eddi d\u00f9ng WinRAR b\u1ecb chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n, \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u ho\u1eb7c m\u00e3 ho\u00e1 d\u1eef li\u1ec7u t\u1ed1ng ti\u1ec1n.<\/p>\n\n\n\n<p>Winrar l\u00e0 m\u1ed9t trong nh\u1eefng ph\u1ea7n m\u1ec1m ph\u1ed5 bi\u1ebfn nh\u1ea5t th\u1ebf gi\u1edbi v\u1edbi c\u00e1ch s\u1eed d\u1ee5ng thu\u1eadn ti\u1ec7n, nhanh ch\u00f3ng v\u00e0 d\u1ec5 d\u00e0ng. Tuy nhi\u00ean, c\u00f3 r\u1ea5t \u00edt ng\u01b0\u1eddi d\u00f9ng l\u1ea1i \u0111\u1ec3 t\u00e2m \u0111\u1ebfn ngu\u1ed3n g\u1ed1c c\u1ee7a Winrar, c\u00e1ch th\u1ee9c n\u00f3 v\u1eadn h\u00e0nh v\u00e0 li\u1ec7u n\u00f3 c\u00f3 an to\u00e0n hay kh\u00f4ng.<\/p>\n\n\n\n<p>Th\u1eadt kh\u00f4ng may, m\u1edbi \u0111\u00e2y \u0111\u00edch th\u00e2n c\u00e1c chuy\u00ean b\u1ea3o m\u1eadt t\u1ea1i Check Point \u0111\u00e3 c\u00f4ng b\u1ed1 v\u1ec1 ph\u00e1t hi\u1ec7n c\u1ee7a h\u1ecd li\u00ean quan \u0111\u1ebfn m\u1ed9t l\u1ed7 h\u1ed5ng c\u1ef1c nguy hi\u1ec3m \u0111\u00e3 t\u1ed3n t\u1ea1i b\u00ean trong WinRAR trong su\u1ed1t h\u01a1n 19 n\u0103m qua.<\/p>\n\n\n\n<p><strong>L\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng c\u00f3 th\u1ec3 \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn n\u1eeda t\u1ef7 ng\u01b0\u1eddi d\u00f9ng<\/strong><\/p>\n\n\n\n<p>C\u00e1c chuy\u00ean gia t\u1ea1i Check Point \u0111\u00e3 c\u00f4ng b\u1ed1 th\u00f4ng tin tr\u00ean t\u1eeb ng\u00e0y 20\/02. H\u1ecd \u0111\u00e3 ph\u00e1t hi\u1ec7n ra trong th\u01b0 vi\u1ec7n m\u00e3 code c\u1ee7a WinRAR c\u00f3 \u1ea9n ch\u1ee9a m\u1ed9t l\u1ed7 h\u1ed5ng, cho ph\u00e9p tin t\u1eb7c ph\u00e1t \u0111i m\u1ed9t m\u00e3 \u0111\u1ed9c v\u00e0 c\u00e0i c\u1eafm v\u00e0o m\u00e1y t\u00ednh c\u1ee7a ng\u01b0\u1eddi d\u00f9ng, t\u1eeb \u0111\u00f3 th\u1ef1c hi\u1ec7n nh\u1eefng h\u00e0nh \u0111\u1ed9ng v\u1edbi m\u1ee5c \u0111\u00edch x\u1ea5u.<\/p>\n\n\n\n<p>C\u1ee5 th\u1ec3 h\u01a1n, l\u1ed7 h\u1ed5ng nguy hi\u1ec3m n\u1eb1m \u1edf t\u1eadp tin th\u01b0 vi\u1ec7n .dll, khi \u0111\u01b0\u1ee3c khai th\u00e1c \u0111\u00fang c\u00e1ch s\u1ebd cho ph\u00e9p hacker chi\u1ebfm ho\u00e0n to\u00e0n quy\u1ec1n ki\u1ec3m so\u00e1t thi\u1ebft b\u1ecb c\u1ee7a n\u1ea1n nh\u00e2n. T\u1eadp tin n\u00e0y c\u00f3 t\u00ean &#8220;unacev2.dll&#8221;, \u0111\u01b0\u1ee3c WinRAR s\u1eed d\u1ee5ng khi \u0111\u1ecdc \u0111\u1ecbnh d\u1ea1ng file n\u00e9n ACE. Khi hacker \u0111\u1ed5i \u0111u\u00f4i c\u1ee7a file n\u00e9n (.ACE) sang th\u00e0nh RAR, ch\u00fang c\u00f3 th\u1ec3 t\u1ea3i n\u1ed9i dung b\u00ean trong file n\u00e9n v\u00e0o m\u00e1y c\u1ee7a ng\u01b0\u1eddi d\u00f9ng ho\u1eb7c c\u00e0i m\u00e3 \u0111\u1ed9c v\u00e0o Windows Startup.<\/p>\n\n\n\n<p> M\u1ed9t chuy\u00ean gia b\u1ea3o m\u1eadt t\u1ea1i Vi\u1ec7t Nam \u0111\u00e3 b\u00ecnh lu\u1eadn v\u1ec1 l\u1ed7 h\u1ed5ng n\u00e0y nh\u01b0 sau:<\/p>\n\n\n\n<p><em>&#8220;K\u1ebb x\u1ea5u c\u00f3 th\u1ec3 l\u1ee3i d\u1ee5ng m\u1ed9t l\u1ed7i b\u1ea3o m\u1eadt khi Winrar \u0111\u1ecdc \u0111\u1ecbnh d\u1ea1ng file n\u00e9n (.ACE). Theo \u0111\u00f3, hacker ch\u1ec9 c\u1ea7n \u0111\u1ed5i \u0111u\u00f4i .ACE ch\u1ee9a m\u00e3 \u0111\u1ed9c (SFX) th\u00e0nh .RAR th\u00ec m\u00e3 \u0111\u1ed9c s\u1ebd \u0111\u01b0\u1ee3c bung v\u00e0o m\u00e1y t\u00ednh n\u1ea1n nh\u00e2n (nh\u01b0 ghi v\u00e0o th\u01b0 m\u1ee5c StartUp). \u0110i\u1ec1u n\u00e0y d\u1eabn t\u1edbi vi\u1ec7c m\u00e1y t\u00ednh n\u1ea1n nh\u00e2n c\u00f3 th\u1ec3 b\u1ecb chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n, \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u ho\u1eb7c m\u00e3 ho\u00e1 d\u1eef li\u1ec7u t\u1ed1ng ti\u1ec1n.&#8221;<\/em><\/p>\n\n\n\n<p><strong>WinRAR nhanh ch\u00f3ng v\u00e1 l\u1ed7i<\/strong><\/p>\n\n\n\n<p>Vi\u1ec7c c\u00f4ng b\u1ed1 m\u1ed9t l\u1ed7i b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng c\u0169ng c\u00f3 ngh\u0129a, n\u00f3 s\u1ebd d\u1ec5 d\u00e0ng b\u1ecb khai th\u00e1c h\u01a1n. Tuy nhi\u00ean c\u00e1c chuy\u00ean gia t\u1ea1i Check Point \u0111\u00e3 nhanh ch\u00f3ng chuy\u1ec3n c\u1ea3nh b\u00e1o th\u00f4ng tin v\u1edbi WinRAR, r\u1ea5t nhanh ch\u00f3ng, WinRAR \u0111\u00e3 \u0111\u01b0a ra m\u1ed9t phi\u00ean b\u1ea3n m\u1edbi nh\u1eb1m v\u00e1 l\u1ed7 h\u1ed5ng nguy hi\u1ec3m.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/farm8.staticflickr.com\/7848\/33307061408_3fda2fac27_o.jpg\" alt=\"\"\/><\/figure>\n<\/div>\n\n\n<p>Website c\u1ee7a WinRAR th\u00f4ng b\u00e1o:<\/p>\n\n\n\n<p><em>&#8220;Nadav Grossman t\u1eeb Check Point Software Technologies \u0111\u00e3 th\u00f4ng tin cho ch\u00fang t\u00f4i v\u1ec1 m\u1ed9t l\u1ed7 h\u1ed5ng b\u1ea3o m\u1eadt \u0111\u1ebfn t\u1eeb file th\u01b0 vi\u1ec7n UNACEV2.DLL. L\u1ed7 h\u1ed5ng n\u00e0y c\u00f3 th\u1ec3 t\u1ea1o ra c\u00e1c t\u1eadp tin trong c\u00e1c th\u01b0 m\u1ee5c t\u00f9y \u00fd, b\u00ean ngo\u00e0i ho\u1eb7c b\u00ean trong th\u01b0 m\u1ee5c \u0111\u00edch khi gi\u1ea3i n\u00e9n file l\u01b0u tr\u1eef ACE&#8221;.<\/em><\/p>\n\n\n\n<p>WinRAR ngay l\u1eadp t\u1ef1c ph\u00e1t h\u00e0nh b\u1ea3n phi\u00ean b\u1ea3n v\u00e1 l\u1ed7i&nbsp;5.70 beta 1, hi\u1ec7n b\u1ea1n c\u00f3 th\u1ec3 t\u1ea3i xu\u1ed1ng theo \u0111\u01b0\u1eddng link&nbsp;t\u1ea1i \u0111\u00e2y&nbsp;\u0111\u1ec3 \u0111\u1ea3m b\u1ea3o an to\u00e0n cho thi\u1ebft b\u1ecb c\u1ee7a m\u00ecnh.<\/p>\n\n\n\n<p> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>L\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng n\u00e0y c\u00f3 th\u1ec3 khi\u1ebfn m\u00e1y t\u00ednh c\u1ee7a n\u1eeda t\u1ef7 ng\u01b0\u1eddi d\u00f9ng WinRAR b\u1ecb chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8422,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-6621","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bao-mat"],"views":344,"_links":{"self":[{"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/posts\/6621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/comments?post=6621"}],"version-history":[{"count":1,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/posts\/6621\/revisions"}],"predecessor-version":[{"id":8423,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/posts\/6621\/revisions\/8423"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/media\/8422"}],"wp:attachment":[{"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/media?parent=6621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/categories?post=6621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tapchicntt.com\/rest-api\/wp\/v2\/tags?post=6621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}