• grue@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    Is there anything special about the “inside a RAR archive” part? Would other archive formats work just as well, or could the maliciously-named file be attached to an email directly?

    • SSUPII@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 day ago

      I don’t see why the archive is important at all here, other than file naming limitations.

      The weak point is from other automated scripts not sanitising the file list when such a file is present, not from the extraction of the archive.

      I really am seeing a nothing burger here.