Risks of downloading .zip files from unknown locations






















I know this is possible in a single line since you can pass bash scripts to fread , but I am not sure how to download a. I found that the following worked for me. I've also used unzip to list the file names within the zip file, so its not necessary to specify the file name s manually. Stack Overflow for Teams — Collaborate and share knowledge with a private group.

Create a free Team What is Teams? Collectives on Stack Overflow. Learn more. Using R to download zipped data file, extract, and import data Ask Question. Asked 11 years, 5 months ago. Active 7 months ago. Viewed k times.

Rstats" I was also trying to do this today, but ended up just downloading the zip file manually. Any thoughts? Jeromy Anglim Jeromy Anglim Did it work?

If so, why would you still feel that you're a long way off? See answers below. Add a comment. Connect and share knowledge within a single location that is structured and easy to search. Now our security team is not allowing zip uploads saying it is a threat. I want to know the security threats by having this feature and what can I do to prevent it.

One area where ZIP files could present a risk to the application the zip bomb attack. It might be possible to mitigate this issue by opening zip files on a dedicated filesystem and then aborting the unzip action if a predetermined maximum size is reached.

The major concerns have already been outlined by other users. However, all of these are either not harmful to the application itself or not specific to zip files. The problem with a zip is that you aren't really sure what's inside of them.

You would need to unzip the contents, scan for virusses and then you know that there aren't any known virusses in them. Second of all, when fileuploads are in use, you can only allow a certain amount of file extensions white list rather than blacklist and you need to verify that the files with this extension are indeed of that type for instance a.

But every type of file can be encapsulated in a zip file. If you whitelist. So again you would need to check the contents of the zip file to make sure only a certain type of files are included in them. So zip would only be feasible in the event that you need to reduce large file uploads that might congest the network. Because to provide security you would still need to unzip them and check the contents.

If you are doing this because you are thinking about conserving diskspace, you are better off accepting the files in normal format and then zipping them yourself after you have checked them. Also zip files are an attack vector vs av engines actually, every file type parsed by av is a vector.

Scenarious of vuln exploitation differ, but they range from something like memory corruption to arbitrary code execution. Sign up to join this community. The best answers are voted up and rise to the top. Stack Overflow for Teams — Collaborate and share knowledge with a private group. Add a comment. Active Oldest Votes. Solutions : If you going to store the zip files as zip files after being uploaded, Doing so you will face additional issues since zips can contain lots of files that may or may not be appropriate.

Community Bot 1 1 1 silver badge. Vinay Vinay 2, 3 3 gold badges 24 24 silver badges 35 35 bronze badges. I have not spoke about users here, I have discussed some of ways to handle zip-files and contents of those zip system side using integration of scanner programs.

John Hunt John Hunt 3, 8 8 gold badges 40 40 silver badges 58 58 bronze badges. Sign up or log in Sign up using Google. Sign up using Facebook. Sign up using Email and Password. Post as a guest Name. Email Required, but never shown.

The Overflow Blog. Podcast what if you could invest in your favorite developer? Thank you! Any more feedback? The more you tell us the more we can help. Can you help us improve? Resolved my issue. Clear instructions. Easy to follow. No jargon. Pictures helped. Didn't match my screen. Incorrect instructions. Too technical. Not enough information.

Not enough pictures.



0コメント

  • 1000 / 1000