Critical .zip vulnerabilities? - Zip Slip and ZipperDown

Channel:
Subscribers:
920,000
Published on ● Video Link: https://www.youtube.com/watch?v=Ry_yb5Oipq0



Duration: 12:30
148,735 views
6,463


What is going on with .zip files. What is this new critical vulnerability that seems to affect everything? ... old is new again.

Resources:
- ZipperDown: https://zipperdown.org/
- Zip Slip: https://snyk.io/research/zip-slip-vulnerability
- Zip Specification: https://pkware.cachefly.net/webdocs/casestudies/APPNOTE.TXT
- The Complete Guide to Hacking WWIV: http://phrack.org/issues/34/5.html#article
- Go library Fix Bypass: https://github.com/mholt/archiver/pull/65#issuecomment-395988244

Gynvael:
- Hacking Livestream #53: The ZIP file format https://www.youtube.com/watch?v=X7j2sisMKzk
- Ten thousand security pitfalls: the ZIP file format http://gynvael.coldwind.pl/?id=682
- GynvaelEN Channel: https://www.youtube.com/GynvaelEN
- Twitter: https://twitter.com/gynvael

Ange Albertini / Corkami
- Funky Fileformats Talk: https://www.youtube.com/watch?v=hdCs6bPM4is
- Funky Fileformats Slides: https://events.ccc.de/congress/2014/Fahrplan/system/attachments/2562/original/Funky_File_Formats.pdf
- Twitter: https://twitter.com/angealbertini / https://twitter.com/corkami

-=[ 🔴 Stuff I use ]=-

→ Microphone:* https://geni.us/ntg3b
→ Graphics tablet:* https://geni.us/wacom-intuos
→ Camera#1 for streaming:* https://geni.us/sony-camera
→ Lens for streaming:* https://geni.us/sony-lense
→ Connect Camera#1 to PC:* https://geni.us/cam-link
→ Keyboard:* https://geni.us/mech-keyboard
→ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ ❤️ Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow
→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ 🐕 Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/
→ Website: https://liveoverflow.com/
→ Subreddit: https://www.reddit.com/r/LiveOverflow/
→ Facebook: https://www.facebook.com/LiveOverflow/

-=[ 📄 P.S. ]=-

All links with "*" are affiliate links.
LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.

#CVE #SecurityResearch







Tags:
Live Overflow
liveoverflow
hacking tutorial
how to hack
exploit tutorial
zip files
zip archive
zip
tar
tar.gz
.zip
.tar
exploiting zip
path traversal
path-traversal
symlink
symbolic link
zipslip
zip slip
zip-slip
zipperdown
phrack
zip attacks
vulnerable
vulnerability
snyk
snyk team
snyk security
pangu lab
pangu team
pangu
disclosure
pull request
gynvael
ange
ange albertini
funky fileformats
file format
archives