
GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload delivery and Windows Startup persistence.
[ SYSTEM ACCESS: GRANTED ] [ TARGET: WINRAR VULNERABILITY ]
A sophisticated, military-grade GUI tool designed for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088). This tool leverages advanced NTFS Alternate Data Streams (ADS) and RAR5 header manipulation to bypass security controls.
# 1. Install required modules
pip install PyQt6
# 2. Launch the exploit console
python gui.py
.exe, .bat).The tool operates in five phases:
..\..\).Target Path: ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
WARNING: AUTHORIZED PERSONNEL ONLY
This tool is for EDUCATIONAL PURPOSES and AUTHORIZED SECURITY TESTING only. The author is not responsible for any misuse or damage caused by this program.
Developed by @XiaoNamdev
Knowledge is power. Use it wisely.