Collected research
HotPics 2021
Server-side image conversion turned into an attack surface: uploading a crafted image makes ImageMagick, Pillow or Ghostscript on the server leak uninitialised memory, read local files, issue requests to internal hosts, or execute commands. Includes a Ghostscript SAFER-mode bypass and bounty cases against AirBNB, Dropbox and Yandex.
Record
- Researcher
- Emil Lerner
- Published by
- Slideshare
- Date
- Format
- Slides
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Emil Lerner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .