Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password protected .7z files #23

Open
enzok opened this issue Jul 26, 2017 · 2 comments
Open

Password protected .7z files #23

enzok opened this issue Jul 26, 2017 · 2 comments

Comments

@enzok
Copy link

enzok commented Jul 26, 2017

I know there's an issue with password protected 7zip files and ZipJail. Is there some workaround for this?

@jbremer
Copy link
Member

jbremer commented Jul 26, 2017

Best would be to implement an additional switch that's explicitly enabled when doing password protected unpacking with 7z, which would then allow the additional thread to be created (as required by 7z).
While working on zipjail once again perhaps we can also brainstorm a bit regarding file unpacking size limits (i.e., prevent zipbombs), cpu resource timeouts, and alike. What are your thoughts? Would you be interested to work on one or more of these issues? :-)
(And also we still have to improve password support in both sflock as well as Cuckoo itself..)

@jbremer
Copy link
Member

jbremer commented Aug 28, 2017

Had some progress here on zipjail side, hatching/tracy@1a2b067. Didn't get to the sflock rewrite (basically it's just that) required to really be able to properly pass along password(s) for decryption.
There are also some issues where 7z properly identifies incorrectly unpacked files (when an incorrect password has been provided), but doesn't delete 'em or something like that. Needs a workaround.

psrok1 pushed a commit to CERT-Polska/sflock that referenced this issue Apr 6, 2023
Add check for compressed format packege
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants