I run TC on Windows 7 32 bit edition. And the same problem has been also confirmed for Vista.
What happens is I enter an encrypted archive from within TC. Then I press F3 to view a file, enter password. TC extracts it into a temporary directory, which in my case is c:\Users\User Name\AppData\Local\Temp\ and lets me view it.
Then I close the main TC window and TC also closes the Lister window as well without any warning. But the temporary file is still in the _TC folder, it is not deleted (while first overwritten with zeros, as it should be) and is there for everyone to see.
I think it's a serious security problem, unless there is something I don't understand.
Security concern/quesion: Temporary folder not deleted!
Moderators: Hacker, petermad, Stefan2, white
- alexinquest
- Junior Member
- Posts: 6
- Joined: 2010-01-25, 20:40 UTC
I create ZIP using packing with password, enter it, open file in Lister and close TC - file left in _tc folder unchanged at all!
BTW, using plugins even more serious problem persists. E.g. yesterday I viewed some files in encrypted 7Z archive, and files left in temp folder unchanged! The problem is that TC can't know if archive is really encrypted. BTW, 7Zip'c caps even don't have flag PK_CAPS_ENCRYPT (0x200) so TC should think that plugin doesn't support encryption. I tried to find if some flag exist that packer returns to TC for encrypted archive, but with no result.
BTW, using plugins even more serious problem persists. E.g. yesterday I viewed some files in encrypted 7Z archive, and files left in temp folder unchanged! The problem is that TC can't know if archive is really encrypted. BTW, 7Zip'c caps even don't have flag PK_CAPS_ENCRYPT (0x200) so TC should think that plugin doesn't support encryption. I tried to find if some flag exist that packer returns to TC for encrypted archive, but with no result.
- ghisler(Author)
- Site Admin
- Posts: 50421
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
About plugins: TC wipes (overwrite with 0) temp files when the plugin reports PK_CAPS_ENCRYPT. If the plugin doesn't report it, TC cannot know that the files were encrypted.
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
- ghisler(Author)
- Site Admin
- Posts: 50421
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact: