Abusing archive-based file formats
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Toggle automatic slides maximization | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Seek 1 frame backward | alt + left arrow |
Seek 1 frame forward | alt + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
You can right click on slides to open the menu
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video stream
Subscribe to notifications
When subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
59 views
If a format structure isn't vulnerable, can that change once wrapped in an archive ?
File formats abuses depend on specific structure characteristics, which makes some file formats not vulnerable. It's however quite common to wrap some formats in specific archive formats.
Combining a format structure with an archive structure may change the outcome, making the result vulnerable by exploiting outside of the box.
Reverse engineer passionate for file formats.
Currently infosec engineer at Google.
Creation date:
July 5, 2022
Speakers:
Ange Albertini
License:
CC BY-SA v4
Links:
Other media in the channel "2022"
21 views, 2 this yearClosingJuly 6th, 2022
59 views, 13 this yearkdigger: A Context Discovery Tool for Kubernetes Penetration TestingJuly 6th, 2022
46 views, 3 this year, 1 this monthDissecting NTLM EPA & building a MitM proxyJuly 6th, 2022
92 views, 30 this year, 2 this monthFinding Java deserialization gadgets with CodeQLJuly 6th, 2022
84 views, 4 this yearMobSF for penetration testersJuly 6th, 2022
82 views, 7 this yearImprove your Malware Recipes with CyberchefJuly 6th, 2022