Light

Episode #937 Quiz

The Man in the Middle
Date: 2023-08-29 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

WinRAR 6.23 fixed CVE-2023-38831, where crafted RAR/ZIP archives with innocuous files and hidden scripts could execute malware when opened; active exploitation targeted traders. HTTPS/TLS protects against passive eavesdropping, but man-in-the-middle attacks require privileged interception. Self-signed certificates secure local devices, and fake storage media can silently falsify capacity, corrupting data.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the WinRAR zero-day described in the episode, what subtle action caused the malicious script to run when the victim interacted with the archive?
Question 2: Why did Gibson say HTTPS/TLS is less necessary on a small local network than on the public Internet?
Question 3: What middle-ground solution did Gibson recommend for local appliances that need browser trust without public CA certificates?
Question 4: Why did the TLS working group draft argue that gmt_unix_time in ClientHello was unnecessary?
Question 5: What did SpinRite discover about the suspicious 256MB flash device that made the failure especially alarming?
Cancel