Skip to content

Add glotfiles to Upload Insecure Files tools - #858

Open
LALITH0110 wants to merge 1 commit into
swisskyrepo:masterfrom
LALITH0110:add-glotfiles-polyglot-generator
Open

Add glotfiles to Upload Insecure Files tools#858
LALITH0110 wants to merge 1 commit into
swisskyrepo:masterfrom
LALITH0110:add-glotfiles-polyglot-generator

Conversation

@LALITH0110

Copy link
Copy Markdown

Adds one entry to the Tools list on the Upload Insecure Files page.

glotfiles is a browser-based generator for polyglot files — single files that are simultaneously valid under two or more format specifications (PDF+ZIP, image+ZIP, PDF+image, and several three- and four-format combinations).

Relevance to this page: the Upload Tricks section already covers swapping magic bytes by hand to get past file type validation. This generates those files directly, which is useful when testing whether an upload filter validates by extension, MIME type, or actual content.

Consistent with the existing entries, it is a hosted tool rather than a repository — same as the Burp and ZAP entries already in that list. Placed alphabetically between them.

Disclosure: I built this tool. No account or installation is required to use it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant