
Episode 132: Archive Testing Methodology with Mathias Karlsson
Critical Thinking - Bug Bounty Podcast
00:00
File Handling and Vulnerabilities in Archives
This chapter explores the technical complexities of file handling within archive systems, focusing on commands for adding and replacing entries in zip and tar formats. It addresses the potential for vulnerabilities, such as unauthorized file execution due to manipulation of archive structures and the impact of Unicode path handling across different systems. The conversation highlights the importance of understanding truncation issues and suggests advanced techniques for testing file paths, enhancing security assessments in file management.
Transcript
Play full episode