Skip to content
← LibraryTechnique entry
W-ZIP-SLIPLateral Movement

Zip Slip / Tar Slip

Crafted archive entry name contains ../ — extraction writes outside the target directory (overwrite cron, authorized_keys, webshell drop).

§ Where this technique fits

W-ZIP-SLIP is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 0 approved dossiers in the registry, typically.