Path: csiph.com!weretis.net!feeder6.news.weretis.net!i2pn.org!i2pn2.org!rocksolid3!.POSTED.rocksolid3!not-for-mail From: Anonymous Newsgroups: rocksolid.shared.security Subject: None Date: Sat, 16 Jan 2021 06:09:03 -0800 Organization: rocksolid3 (rocksolidbbs.com) Message-ID: References: Content-Type: text/plain; charset=UTF-8 Injection-Info: rocksolidbbs.com; posting-host="rocksolid3:10.128.3.129"; logging-data="4376"; mail-complaints-to="usenet@rocksolidbbs.com" Xref: csiph.com rocksolid.shared.security:63 >>acdc5a9b4367c051b2 unzip $file, tar -xf $file, cpio -i -F $file, mkdir $garbage, touch $garbage, mv file $garbage, etc. It's similar not the same but from a quick search ntfs and redsea have the same fundamental flaws so this method can also be used. This is not anything special, it's bad filesystem design. Make inodes with names out of the utf8 range until the filesystem corrupts and loses data. Difficulty is on how resilient the filesystem is, this isn't a new concept so it won't work easily on modern filesystems. Bonus points for making random shell commands launch or all of the superblocks, journal and root inode lost. This isn't significant unless you can make a poc that directly targets the root inode and all the superblocks, permanently trashing the filesystem, with great accuracy. -- Posted on def2