Security concern/quesion: Temporary folder not deleted!

Bug reports will be moved here when the described bug has been fixed

Moderators: white, Hacker, petermad, Stefan2

Post Reply
User avatar
alexinquest
Junior Member
Junior Member
Posts: 6
Joined: 2010-01-25, 20:40 UTC

Security concern/quesion: Temporary folder not deleted!

Post by *alexinquest »

I run TC on Windows 7 32 bit edition. And the same problem has been also confirmed for Vista.

What happens is I enter an encrypted archive from within TC. Then I press F3 to view a file, enter password. TC extracts it into a temporary directory, which in my case is c:\Users\User Name\AppData\Local\Temp\ and lets me view it.
Then I close the main TC window and TC also closes the Lister window as well without any warning. But the temporary file is still in the _TC folder, it is not deleted (while first overwritten with zeros, as it should be) and is there for everyone to see.

I think it's a serious security problem, unless there is something I don't understand.
User avatar
MVV
Power Member
Power Member
Posts: 8702
Joined: 2008-08-03, 12:51 UTC
Location: Russian Federation

Post by *MVV »

I create ZIP using packing with password, enter it, open file in Lister and close TC - file left in _tc folder unchanged at all!

BTW, using plugins even more serious problem persists. E.g. yesterday I viewed some files in encrypted 7Z archive, and files left in temp folder unchanged! The problem is that TC can't know if archive is really encrypted. BTW, 7Zip'c caps even don't have flag PK_CAPS_ENCRYPT (0x200) so TC should think that plugin doesn't support encryption. I tried to find if some flag exist that packer returns to TC for encrypted archive, but with no result.
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 48173
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Post by *ghisler(Author) »

About plugins: TC wipes (overwrite with 0) temp files when the plugin reports PK_CAPS_ENCRYPT. If the plugin doesn't report it, TC cannot know that the files were encrypted.
Author of Total Commander
https://www.ghisler.com
User avatar
DrShark
Power Member
Power Member
Posts: 1872
Joined: 2006-11-03, 22:26 UTC
Location: Kyiv, 68/262
Contact:

Post by *DrShark »

Confirm fix in 7.55pb1.
Donate for Ukraine to help stop Russian invasion!
Ukraine's National Bank special bank account:
UA843000010000000047330992708
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 48173
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Post by *ghisler(Author) »

Thanks!
Author of Total Commander
https://www.ghisler.com
Post Reply