3 ms·
Even if it's in a box, you need to pull the thing you want back out of the box. A malicious file could put a payload into the destination file.
by Splines 10y ago
Even if it's in a box, you need to pull the thing you want back out of the box. A malicious file could put a payload into the destination file.
- tekklloneer 10y agoYes, by containing the payload and decompressing it. The difference is that by not sandboxing it, that malicious file could also cause its payload to be executed in the permission scope of the decompressor.
- Animats 10y agoThat's pointless. Putting the malicious file in the archive would accomplish the same result.