ACE (compressed file format)
This article relies largely or entirely on a single source. (February 2016)
|Internet media type|
|Developed by||e-merge GmbH|
|Type of format||data compression|
In computing, ACE is a proprietary data compression archive file format developed by Marcel Lemke, and later bought by e-merge GmbH. The peak of its popularity was 1999–2001, when it provided slightly better compression rates than RAR, which has since become more popular.
WinAce, maintained by e-merge GmbH, is used to compress and decompress ACE files under Microsoft Windows. When installed, it lets the user choose between paying for a registration or installing WhenU SaveNow adware. e-merge GmbH also produces a Commandline ACE for DOS; and a freeware command-line interface decompression tool for Linux (i386) and macOS called "Unace". e-merge GmbH also provides several libraries for developers, including a freeware decompression DLL called "UnACE.DLL". Some third-party archivers can read the format using this DLL. None of the above is open source free software.
On November 23, 2007, version 2.69 of WinACE was released, including a less-intrusive adware application, MeMedia AdVantage, which replaces WhenU. No other major changes are in this release.
A newer version of Unace 2.5 that supports ACE 2.0 archives is available under a restrictive open source license, also by Marcel Lemke.
Packing of ACE files is licensed as proprietary information and only available through WinACE, while unpacking of ACE files is supported by a number of third-party archivers. However, virtually all of them (the ones that support ACE 2.x format) do this by using the proprietary "Unace.dll" from e-merge GmbH.
Use for malware distribution
Since at least 2015, ACE archives have been used to deliver malware to victims by e-mail. This tactic was viable because popular archiving software was able to uncompress ACE archives, but support for the ACE format in security products such as mail filters, web content filters and anti-virus software was generally weak.
In February 2019 several major security vulnerabilities were found in the UnACEv2.dll library which is used by WinRAR and other archiving products. Since WinACE is abandonware, users are advised against opening ACE archives in WinRAR and possibly other products using this library. WinRAR stopped supporting ACE as of version 5.70, and similar products are following suit.
- "unace: extract, test and view .ace archives". Debian.
- "unace-nonfree: extract, test and view .ace archives (non-free version)". Debian.
- "acefile: Read/test/extract ACE 1.0 and 2.0 archives in pure python". PyPI. Retrieved 2019-03-09.
- "Malware sent in .ace format". Frank Leonhardt's blog. Retrieved 2019-03-09.
- "Spammers discover the 7z archive format for spreading ransomware". IBM X-Force Exchange. Retrieved 2019-03-09.
- "How to deal with .ACE malware files?". Marc Rivero López' blog. Retrieved 2019-03-09.
- "Extracting a 19 Year Old Code Execution from WinRAR". Check Point Research. 2019-02-20. Retrieved 2019-02-26.