Page 1 of 2

Děravý WinRAR plugin?

Posted: 22 Aug 2023, 15:37
by AD7
Vie niekto potvrdiť či sa to týka AS 4.0?

https://www.zive.cz/clanky/deravy-winra ... fault.aspx

Vďaka.

---
PS: Ak áno, ide s tým čosi urobiť?

Re: Děravý WinRAR plugin?

Posted: 23 Aug 2023, 17:04
by therube
Oh, to nevěděl bych?

Můžete si však stáhnout UnRAR.dll.

Ve skutečnosti je to .exe [jednoduše přejmenujte na .exe.RAR] a uvnitř je UnRAR64.dll (verze 6.23).
Přejmenujte to na UnRAR.dll.
Nahraďte existující unrar.dll souborem UnRAR.dll.

Je to otřesný způsob, jak dělat věci, a nemám ponětí, jestli by s tím byly nějaké problémy, ale zdá se, že to funguje.
Můžete to tedy zkusit a zjistit, zda to stačí.

---

Oh, I wouldn't know?

But, you can download UnRAR.dll.

It's actually an .exe [simply rename to .exe.RAR] & inside is UnRAR64.dll (version 6.23).
Rename that to UnRAR.dll.
Replace the existing unrar.dll with UnRAR.dll.

That's a hacky way to do things, & no idea if there would be any gotcha's with that, but it seems to work.
So you could try it & see if doing that is sufficient.

Re: Děravý WinRAR plugin?

Posted: 23 Aug 2023, 21:13
by AD7
Díky. Aktualizované.

Re: Děravý WinRAR plugin?

Posted: 25 Aug 2023, 20:31
by engy
Podle posledních informací jsou DLL knihovny OK
https://www.rarlab.com/vuln_rev3_names.html

According to the latest information, the DLLs are OK
https://www.rarlab.com/vuln_rev3_names.html

Re: Děravý WinRAR plugin?

Posted: 28 Aug 2023, 10:34
by Sam
therube wrote: 23 Aug 2023, 17:04 Oh, to nevěděl bych?

Můžete si však stáhnout UnRAR.dll.

Ve skutečnosti je to .exe [jednoduše přejmenujte na .exe.RAR] a uvnitř je UnRAR64.dll (verze 6.23).
Přejmenujte to na UnRAR.dll.
Nahraďte existující unrar.dll souborem UnRAR.dll.

Je to otřesný způsob, jak dělat věci, a nemám ponětí, jestli by s tím byly nějaké problémy, ale zdá se, že to funguje.
Můžete to tedy zkusit a zjistit, zda to stačí.

---

Oh, I wouldn't know?

But, you can download UnRAR.dll.

It's actually an .exe [simply rename to .exe.RAR] & inside is UnRAR64.dll (version 6.23).
Rename that to UnRAR.dll.
Replace the existing unrar.dll with UnRAR.dll.

That's a hacky way to do things, & no idea if there would be any gotcha's with that, but it seems to work.
So you could try it & see if doing that is sufficient.
Yes, that is, what we would expect.
Sorry, I beg pardon, I can't speak any word Czech. (only German and English)
Hope you can read.

When I read about the bug, some days ago, I instantly intuitively replaced the unrar.dll with the newer one.
But when "diving into" (clicking on) a Rar5 Archive Servant quits the plugin with an error message:
"Servant cannot load the library unrar.dll - is no valid win32 application"
and
"UnRAR plugin is not loaded. plugin is no Altap Salamander plugin or plugin has internal error"

(I examined the (given) unrar.dll, by myself, too, and anyhow it says, it is no usual win32 application, too - oops! - only the unrar.spl seems to be and .... anyhow it's size is 320.728 whereas the newer, precompiled UnRAR.dll from winrar Homepage has 291.928 bytes only. Did they compile it themselves :mrgreen: )

Setting Options to "opening rar with Winrar" and position of WinRar -> C:\Winrar\bla\unrar.exe Servant shows empty archive = "nothing", when "clicking on an archive ".

... Seems, command -v is unknown to Winrar / unrar >v2.50

So, the only way - we can set it back to plugin and hope that no one clicks on prepared archives :mrgreen: ...

Good luck! :lol:

Re: Děravý WinRAR plugin?

Posted: 04 Sep 2023, 09:43
by SelfMan
Sorry for later confirmation of the post. I am on the road.

Re: Děravý WinRAR plugin?

Posted: 05 Sep 2023, 18:14
by therube
You need to match the "bit-ness" of the .dll that you use.

If Salamander x86, you want UnRAR.dll (x86) [291.928].
If Salamander x64, you want UnRAR64.dll (x64), though you then also need to rename UnRAR64.dll to UnRAR.dll [346.200].

Re: Děravý WinRAR plugin?

Posted: 05 Oct 2023, 19:57
by therube
WinRAR Version 6.24 is released (along with an update to UnRAR), & this (exploit) is mentioned.
So if you updated the .dll before (it was v6.23 at the time), you might want to do it, again.

(And test, to make sure you're not running into issues ;-).)

Re: Děravý WinRAR plugin?

Posted: 08 Oct 2023, 14:54
by AD7
Díky, za pripomenutie.

Re: Děravý WinRAR plugin?

Posted: 11 Oct 2023, 20:35
by Sam
hm, well I tried to copy current unrar.dll from RAR-homepage into the /plugin/unrar-directory.
I have installed Salamander 64 bit, so I copied the 64 bit unrar.dll beneath the unrar.spl.

But everytime I broswe into a rar file, I get two kinds of errors:

one, which regularly appears, is that filenames and dates a shown as "kyrillic" like long strings,
example.png
example.png (2.9 KiB) Viewed 35292 times
or sometimes occurs: Packer Fehler (means "Packer Error")
Datum und/ oder Zeit der Datei im Archiv sind falsch (means: "Date or time of the files in the file archive are wrong")
dateti.png
dateti.png (2.35 KiB) Viewed 35292 times

later: Also renaming back the old hidden unrar.dll that came with and removing the newer dlls and starting Salamander a second time, does not work now anymore. WTF?! (OK, every without browsing rar files seems to work)
how can it be, that when I restore all° - I cannot now still can't browse rar files with old unrar.dll in directory, too ???

°= (restored situation is shown in big screenshot blow)
sammy.png
sammy.png (48.3 KiB) Viewed 35292 times
What did you do as workaround to brows rar files as usual?
Why does Total Commander does not have problems with this?? (and why/how he supports TABs ??? [in 2023 ....] :D)

Re: Děravý WinRAR plugin?

Posted: 11 Oct 2023, 23:45
by AD7
I have bought WinRAR that I use most of the time.
Internal plugin I use only sometimes.

Re: Děravý WinRAR plugin?

Posted: 11 Oct 2023, 23:57
by SelfMan
I don't know whet you did exactly, but it's working for me just fine.

Re: Děravý WinRAR plugin?

Posted: 12 Oct 2023, 02:52
by Sam
AD7 wrote: 11 Oct 2023, 23:45 I have bought WinRAR that I use most of the time.
Internal plugin I use only sometimes.
I have bought WinRAR several years ago and I use it sepeately for browsing, too. (have set WinRAR in Salamander F9 Menu)
But it is more handy/ quicker to browse with Salamander before running other programs.
SelfMan wrote: 11 Oct 2023, 23:57 I don't know whet you did exactly, but it's working for me just fine.
I just downloaded the new DLL (64bit) from RAR Homepage and copied it into the special plugin directory and started Salamander. But browsing RAR files does not show the contend as usual. (see screenshots above)

Then I also download the free Salander 4.0 (64bit) again from here,
deleted the registry values (Altap), renamed the folder,
installed Salamander again
copied the unrar.dll (64bit) into the plugin directory and overwrote the old one.
Started Salamander - and - the same ...

I have no idea, what could be gone wrong?

Re: Děravý WinRAR plugin?

Posted: 12 Oct 2023, 08:54
by SelfMan
ok, let's try again
- download unrar dll package from https://www.rarlab.com/rar/unrardll-624.exe
- extract the package (don'r run it)
- go to x64 folder in the extracted one and rename UnRAR64.dll to UnRAR.dll
- close Salamander (id running)
- copy renamed UnRAR.dll file to "C:\Program Files\Altap Salamander\plugins\unrar" (make backup od the original)
- start Salamander

That's all

Re: Děravý WinRAR plugin?

Posted: 19 Oct 2023, 17:09
by AD7
Už bijú na poplach aj na Živě.cz :wink:

https://www.zive.cz/clanky/mate-li-winr ... fault.aspx