← Graph

Image bomb

concept 3 connections

Attack vector (introduced to Janko by Evil Martians) in which an attacker crafts an image file that is small in file size but extreme in pixel dimensions. When the server-side image processor decodes it, memory usage explodes and the process crashes. Mitigated by validating image dimensions (not only file size) on upload.

category
security
about
Image bomb concept
Explains why dimension validation is needed.
about
Image bomb concept
Explicitly addresses the image-bomb attack.
company Evil Martians
related_to
Image bomb concept
Introduced Janko to the image-bomb attack idea.

Provenance

Read by
3 extractions