gpt4 book ai didi

zip - 如何从命令行创建文件以测试 Zip Slip 漏洞

转载 作者:行者123 更新时间:2023-12-04 03:09:54 25 4
gpt4 key购买 nike

来自 https://snyk.io/research/zip-slip-vulnerability

The contents of this zip file have to be hand crafted. Archive creation tools don’t typically allow users to add files with these paths, despite the zip specification allowing it. However, with the right tools, it’s easy to create files with these paths.



我想创建一个测试负载,以便我可以检查一些我的 zip 处理逻辑。但我找不到任何关于如何创建一个的线索。
:~/Desktop # touch "../../../../../../../../tmp/evil.sh"
:~/Desktop # ll
:~/Desktop # ll /tmp/evil.sh
-rw-r--r-- 1 root root 0 Jun 14 09:27 /tmp/evil.sh

最佳答案

也许

zip zipslip.zip ../../../../../../../../tmp/evil.sh

关于zip - 如何从命令行创建文件以测试 Zip Slip 漏洞,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/50849406/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com