Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
RAR-Anomaly-Inspector — 防御性PowerShell工具,用于静态检查RAR归档文件并检测CVE-2025-8088路径遍历异常。 | Kitploit
工具/GitHubGitHub/ilhamrzr/rar-anomaly-inspector
防御工具静态分析漏洞分析取证分析恶意软件分析事件响应
GitHubilhamrzr/rar-anomaly-inspector

RAR-Anomaly-Inspector

防御性PowerShell工具,用于静态检查RAR归档文件并检测CVE-2025-8088路径遍历异常。

查看仓库
1128个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

RAR 异常检查器

License MIT PowerShell 5.1+ CVE-2025-8088

RAR Anomaly Inspector 是一个只读的 PowerShell 工具,用于静态检查 RAR 存档,旨在检测与 CVE-2025-8088 (WinRAR RAR5 路径遍历) 相关的路径遍历异常。

该工具不会提取或执行存档内容。


功能特点

  • 静态、只读分析(无提取、无执行)
  • 检测原始路径遍历模式(..\)
  • 识别提取目录外的写入操作
  • 检测 NTFS 备用数据流 (ADS) 指示器
  • 干净、仅目录的输出(适合复制粘贴)
  • 基于启发式的风险分类

系统要求

  • Windows
  • PowerShell 5.1+
  • 可选:7z.exe(用于列出用户可见的文件)

使用方法

.\anom-rar.ps1 .\suspicious.rar

示例输出

RAR Anomaly Inspector
CVE      : CVE-2025-8088 (WinRAR Path Traversal)
Author   : Ilham
Source   : https://github.com/ilhamrzr/RAR-Anomaly-Inspector

Mode     : Static / Read-Only Inspection
Warning  : Indicators only - NOT proof of exploitation
ScanTime : 2026-01-11 13:33:05
-------------------------------------------------------

=== Archive File Inventory (7-Zip read-only) ===
Files visible to the user:
  - CVE-2025-8088.pdf

=== Suspicious Path Indicators Extraction ===
RAW suspicious path indicators (UNFILTERED):
  - ..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
  - ..\..\..\..\..\..\..\..\..\..\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CVE-2025-8088.vbs
Total RAW indicators: 10

Sanitized logical paths (SAFE for copy-paste):
  -> AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

=== Summary ===
Result: [!] ARCHIVE REQUIRES FURTHER INVESTIGATION
[!] High-risk archive structure detected (repeated deep traversal / ADS-style metadata)

Manual investigation hint:
- Review archive construction and intent.
- Do NOT execute extracted files directly.
- Treat repeated traversal as HIGH RISK.

Inspection completete.



风险级别

  • 低
    无明显敏感目标的轻微异常

  • 中
    检测到遍历但无明确持久化路径

  • 高
    明确针对敏感目录的遍历

风险级别为启发式判断,并不表示利用成功。


本工具不执行的操作

  • 不提取存档

  • 不执行文件

  • 不验证有效载荷

  • 不保证利用性


适用范围

  • 适用于防御性分析和分类

  • 适合蓝队、响应人员和研究人员

  • 非利用框架


CVE 参考

  • CVE-2025-8088

  • 受影响:Windows 版 WinRAR ≤ 7.12

  • 修复版本:WinRAR 7.13+


免责声明

本工具仅供防御和教育目的使用。

下载工具