Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Further context: https://www.da.vidbuchanan.co.uk/blog/exploiting-acropalypse...

You should notice that the file size didn't actually get any smaller after you cropped it. The full-size image file is not truncated before the cropped version is written. The left-behind data can be recovered.



The root cause seem to be an open mode which opens the original file for writing without truncation, but writing to the original file directly in the first place seemed precarious. The software I use tend to write to a temporary file first and then do a rename to replace the original file.

The bit about recovering LZ77 stream without the prefix sounds very useful as a data recovery tool.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: