Quantcast
Channel: Total Commander
Viewing all articles
Browse latest Browse all 18761

Eng :: RE: encrypted ZIPs unsafe -> easy to decrypt without password

$
0
0
Author: jazzz
Posted: Tue Dec 27, 2016 4:21 am (GMT -6)

Sorry, it's not the tickbox..

But my description was not 100% clear, let me explain in more detail:

- I get a set of files in a dir -> create the encrypted zip (pw "asd" )
- I change dir contents in the left pane (add some files)
- in the right pane I open the zip (no pw asked)
- using Sync dir, I get "pw required! error unpacking (wrong pw?)"
- I use "q" as pw
- I re-enter "q" as pw
- content is synced!

Please try harder, the above is my usual workflow. After testing now with a new zip and new data, the same happened.

And more funny stuff. If I add files in the encr. zip using a 3rd new random pw "z" (which means anyone can compromise my zipfile!!), I can only copy it out with that same 3rd pw "z".

But in Sync dir., I can copy the file out of the zip with the old pw ("q"). But it get's todays timestamp, gets corrupted (an unreadble pdf in this case), and of course, in the next sync it wants to enter the zip since it is considered to be a more recent file..

So please try again with a dir + files in one pane and an encrypted zip in the other. All funny things are possible, and certainly not secure.

It's not new, I saw this half a year ago..


Viewing all articles
Browse latest Browse all 18761

Trending Articles