4 ms·
Can the malicious video file be an actual mp4 file? We're accepting video and running it through ffmpeg, however we first verify the file is an mp4 using https:
by anonfunction 11y ago
Can the malicious video file be an actual mp4 file? We're accepting video and running it through ffmpeg, however we first verify the file is an mp4 using https://golang.org/src/net/http/sniff.go https://golang.org/src/net/http/sniff.go
- ChALkeR 11y agoBut that code that you linked to does not verify that the file is mp4, moreover, mp4Sig call is commented out.
- anonfunction 11y agoIt verifies that the beginning of a file is mp4 format. I'm actually running go 1.6 which does have the mp4 sniffing enabled.
- IceyEC 11y agoI was under the impression than MP4 could have all of its format specific headers at the end of the file just as well as the beginning according to the spec.
- anonfunction 11y agoThat is correct, however the beginning of the file does have a signature: https://mimesniff.spec.whatwg.org/#signature-for-mp4 https://mimesniff.spec.whatwg.org/#signature-for-mp4
- ryanlol 11y agoPossibly? Who knows? Parsers are complex and I doubt ffmpeg relies on file extensions to figure out the format.
- ChALkeR 11y agoIt does not, that's covered in the original article.
- anonfunction 11y agoIt does not what? Can you share quotes from the article or the translated article source you read? Confusion: Are you saying that ffmpeg doesn't detect file by extension? or Are you saying that ffmpeg won't execute the malicious code if it's found appended to a valid video?