When someone hands you a password-protected ZIP archive, one’s immediate thought is:
“I need to break the password”.
For most modern archives, that is exactly the case, and the password is the whole game. But there is a family of ZIP archives where the password does not matter at all. It can be four characters or forty, random or memorable, if the archive uses the legacy ZIP encryption, the whole thing can be unlocked in minutes without ever guessing the password.
This is one of the oldest tricks in our line of work, and it is worth telling the story properly, because it is equal parts computer history and practical forensics 🔑
A word of caution before we start. The attack we are about to describe applies to the classic ZIP 2.0 encryption, the scheme Phil Katz built into PKZIP in the late eighties. Almost nobody should be creating archives with it today. Modern archivers default to AES, which is a completely different situation.
So treat most of this article as a fascinating piece of history, with a long and narrow tail of cases where it still bites in real life.
More information at the link📎
