Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Disable symlinks and check for path traversal
- Loading branch information
1 parent
ffebfa3
commit 3dd165b
Showing
6 changed files
with
46 additions
and
40 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,10 @@ | ||
# Based on 'relative2' in https://github.com/jwilk/path-traversal-samples, | ||
# but create the local `tmp` folder before adding the symlink. Otherwise | ||
# we may bail out before we get to trying to create the file. | ||
all: relative1.zip | ||
relative1.zip: | ||
rm -f $(@) | ||
mkdir -p -m 755 tmp/tmp | ||
umask 022 && echo moo > moo | ||
cd tmp && zip -X ../$(@) tmp tmp/../../moo | ||
rm -rf tmp moo |
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,3 +1,3 @@ | ||
# Path Traversal Samples | ||
|
||
Copied from https://github.com/jwilk/path-traversal-samples on 2018-08-25. | ||
Copied from https://github.com/tuzovakaoff/zip_path_traversal on 2018-08-25. |
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters