Web Hack List

Collected research

HotPics 2021

Server-side image conversion turned into an attack surface: uploading a crafted image makes ImageMagick, Pillow or Ghostscript on the server leak uninitialised memory, read local files, issue requests to internal hosts, or execute commands. Includes a Ghostscript SAFER-mode bypass and bounty cases against AirBNB, Dropbox and Yandex.

Record

Researcher
Emil Lerner
Published by
Slideshare
Date
Format
Slides
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Emil Lerner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .