WinRAR, sanannen kuma tsohon mai amfani, an gano shi a watan da ya gabata ya kasance mai saurin kamuwa da kwaro tsawon shekaru 19 da suka gabata, cikin sauƙi masu satar bayanai da masu rarraba malware ke amfani da su. Abin farin ciki, an daidaita software a cikin ginin kwanan nan 5.70. Koyaya, masu amfani da yawa ba su sabunta shirin ba na dogon lokaci ko ma da wuya, don haka sabon igiyoyin malware yanzu suna amfani da batun sosai.

Masu binciken tsaro na Check Point, wadanda suka gano raunin, sun bayyana cewa ana amfani da aibi na ma'ajiyar ta hanyar rarraba ma'ajiya ta RAR, wanda ke fitar da muggan code kai tsaye idan an bude shi. Waɗannan shirye-shiryen suna shigar da kansu a cikin babban fayil ɗin farawa na PC sannan suna aiki a duk lokacin da kwamfutar ta kunna, duk ba tare da sanin mai amfani ba.

Da zarar an bayyana bug din, kungiyoyin masu satar bayanai sun fara amfani da shi, kuma kasashe daban-daban sun zama masu kai hare-hare ta yanar gizo da nufin tattara bayanan sirri. Kamfanin tsaro na software McAfee ya lura cewa ya riga ya gano sama da 100 na musamman na amfani da kwaro na WinRAR, mafi yawansu sun yi niyya ga Amurka.
Masu rarraba malware suna sane da shaharar WinRAR a tsakanin waɗanda suka fi son sauke fayilolin mai jarida daban-daban ba bisa ka'ida ba. McAfee ya lura cewa ɗaya daga cikin mashahuran cin zarafi yana kaiwa waɗanda ke neman kan layi don kwafin kwafin sabon kundi na Ariana Grande, "Na gode U, Na gaba."
WinRAR amfani (#CVE-2018-20250) samfurin (ƙasashen .rar) da alama yana nufin Gabas ta Tsakiya. Cike da takardun koto da suka shafi Majalisar Dinkin Duniya 'Yancin Dan Adam da #UN a Larabci, a karshe ta zazzage kuma ta aiwatar da #Revenge RAT.https://t.co/WJ4oJ1UxAz pic.twitter.com/fgHYSD4Mk5
- Cibiyar Leken asiri ta 360 (@360TIC) Maris 12, 2019
Tabbas, WinRAR ba ya kusa da sananne a yau kamar yadda ya kasance shekaru da yawa da suka gabata, amma tare da tushen masu amfani da shi ya kai miliyan 500 a cikin kusan shekaru 20, ba zai yuwu a faɗi tsarin nawa ne ke da rauni ga wannan harin ba. Bugu da ƙari, duk da cewa an fitar da sigar 5.70 a ƙarshen Janairu, har yanzu tana buƙatar saukarwa da shigarwa da hannu daga gidan yanar gizon hukuma, yana barin yawancin masu amfani ba su san wannan sabuntawa mai mahimmanci ba.
source: 3dnews.ru
