logo

Abusing File Converters

ID: 2c7ed409-0857-5421-9eb0-7d6546c57184

STIX ID: report--2c7ed409-0857-5421-9eb0-7d6546c57184

Feed Name: SensePost Blog

Threat Score
50/100

Date Published: 2015-10-01

Date Updated: 2026-04-29

...
...

The report demonstrates an attack technique against online file conversion services: uploading an archive containing symbolic links can cause the conversion process to resolve those symlinks and include sensitive server-side files in the converted download (e.g., /etc/passwd), resulting in arbitrary file disclosure limited by file permissions and attacker knowledge of paths. The author shows creating a zip with preserved symlinks and converting it to a format that doesn't support symlinks (like RAR) to force inclusion of linked files; symlinking directories can expand impact. The conversion provider acknowledged the behavior and isolates conversions using newly spawned Docker containers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.