Hacking fun with zip-slips, tar-slips, symlinks, hardlinks, collisions, and more (opens in new tab)
A tool and walk-through for building zip, tar, 7z, and rar archives that trigger zip-slip and tar-slip edge-cases: path traversal, symlink and hardlink collisions, read-only files, and more, for testing extractors during a pentest.
Read the original article