Jan. 14, 2024, 11:24 a.m. | Serhat ÇİÇEK

InfoSec Write-ups - Medium infosecwriteups.com

Zip Slip Vulnerability

The Zip Slip vulnerability revolves around the unsafe extraction of compressed files within applications. It occurs when software mishandles paths embedded within zipped archives during extraction. This flaw enables attackers to manipulate file paths, potentially leading to the extraction of sensitive files beyond the intended folders. Essentially, Zip Slip poses a risk by allowing malicious actors to navigate through directories, gaining access to critical system files and compromising application security.

In this article we will understand zip …

applications archives attackers beyond embedded extraction file files flaw folders hacking malicious penetration testing risk sensitive software vulnerability web hacking web security zip zipped

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Application Security Engineer - Enterprise Engineering

@ Meta | Bellevue, WA | Seattle, WA | New York City | Fremont, CA

Security Engineer

@ Retool | San Francisco, CA

Senior Product Security Analyst

@ Boeing | USA - Seattle, WA

Junior Governance, Risk and Compliance (GRC) and Operations Support Analyst

@ McKenzie Intelligence Services | United Kingdom - Remote

GRC Integrity Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City