>_0xFORUM
Sign in

Path traversal in a zip extract, the zip-slip class, still

in Exploits22 replies2.1k views

Yes still. A desktop app extracted a theme zip. Patched with a prefix check. I want test zips that are legal and mean, not malware.

If your extractor does not reject .. , it is not an extractor. It is a copy into nowhere.

Refs: CVE Program

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 22 REPLIES

I dumped after OEP and then did this. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

@encodr

Not fully convinced yet. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. Vendor bump is patch Tuesday. Forgotten

You are describing a live target. Stop. Patched class only. I want the listing, not the decompiler story. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. If you wrap memcpy, I want the check on every path. I still have the snapshot named expl-234-pre.

@dropx

I dumped after OEP and then did this. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. Vendor bump is

Not fully convinced yet. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Pinned a comment at 0x140002e4d in the listing.

Came back to this after a coffee. Still hold. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Which build of the tool? I got burned mixing notes across versions. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. If you wrap memcpy, I want the check on every path. If anyone DMs me a zip I will not open it. Hash in-thread.

@hexbit

I tried the naive path first and wasted a morning. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. If

Quote the bytes or sit down. This belongs in the first-hour ritual. The load-bearing line: Yes still. Date your heap notes. 2012 grooming diagrams are history. I will +rep a listing and −rep a vibe. That is the deal.

I want the listing, not the decompiler story. The load-bearing line: Yes still. Date your heap notes. 2012 grooming diagrams are history. What did you key the join on — PID or process GUID? Same class as the January thread, different binary.

Not fully convinced yet. You wrote «Yes still». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Same class as the October thread, different binary.

@gamma

Came back to this after a coffee. Still hold. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. Patched class only

I would have written the opposite conclusion a year ago. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. Patched class only. Hunt the old immediate. Do not ask for a trigger file. Version in my shot: current lab snapshot, not last year's blog.

@lambd

I failed this exact class in January. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. Vendor bump is

You skipped isolation and then asked why the box is dirty. That is on you. I would have written the opposite conclusion a year ago. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. OOB read is a leak until proven otherwise. In the notes, not in a PoC. My note id for this: ea-10.

@idx

This belongs in the first-hour ritual. The load-bearing line: Yes still. Date your heap notes. 2012 grooming diagrams are history. I will +r

I want the listing, not the decompiler story. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. system() on a user path is the class. execve with argv is the patch. Pinned a comment at 0x140002b88 in the listing.

I failed this exact class in January. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. Vendor bump is patch Tuesday. Forgotten trees grow extra years. Version in my shot: current lab snapshot, not last year's blog.

I tried the naive path first and wasted a morning. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

Also: If you wrap memcpy, I want the check on every path.

@nite

I tried the naive path first and wasted a morning. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. If you wrap m

This is the writeup I wanted when I was stuck. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. A saturating add that hangs is not a complete patch. Hunt the hang too. Was this on the licensed corpus or a crackme you wrote? Version in my shot: current lab snapshot, not last year's blog.

@omega

This is the writeup I wanted when I was stuck. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. A satu

That is not what the listing shows. You are arguing a vibe. I still keep a paper notebook for this kind of note. The load-bearing line: Yes still. No samples, even public corpus files. Hashes and links. Attachments get pulled. Pinned a comment at 0x140004d5b in the listing.

I disagree with the tone, not the bytes. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. system() on a user path is the class. execve with argv is the patch. I will +rep a listing and −rep a vibe. That is the deal.

@r4dio

I disagree with the tone, not the bytes. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. system() on

This matches a public n-day class from last patch Tuesday. You wrote «Yes still». That is the sentence I keep. If you wrap memcpy, I want the check on every path. I will +rep a listing and −rep a vibe. That is the deal.

Please keep the hashes and drop the mystery zips. The load-bearing line: Yes still. Vendor bump is patch Tuesday. Forgotten trees grow extra years. I wrote a 12-line script and then threw it away. The listing was enough.

@seyiwave

Please keep the hashes and drop the mystery zips. The load-bearing line: Yes still. Vendor bump is patch Tuesday. Forgotten trees grow extra

Call-convention guess is not evidence. I dumped after OEP and then did this. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. system() on a user path is the class. execve with argv is the patch. Did page heap see it, or only the sanitizer? I still have the snapshot named expl-234-pre.

@sockx

I dumped after OEP and then did this. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. system() on a user path is

Bookmarking this for the lab wiki. On «Path traversal in a zip extract, the zip-slip class, still»: Yes still. If you wrap memcpy, I want the check on every path. I still have the snapshot named expl-234-pre.

Please keep the hashes and drop the mystery zips. «Path traversal in a zip extract, the zip-slip class, still» — specifically Yes still. Date your heap notes. 2012 grooming diagrams are history. Same class as the October thread, different binary.

Also: OOB read is a leak until proven otherwise. In the notes, not in a PoC.

I want the listing, not the decompiler story. You wrote «Yes still». That is the sentence I keep. Date your heap notes. 2012 grooming diagrams are history. Took me 12 hours the first time.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.