Reply to post:

Alert: 15-year-old Python tarfile flaw lurks in 'over 350,000' code projects

John Robson Silver badge

from / the path ../ is just /, so ../../../../../../../../../../../../../../../../../../ is almost certain to be the root of the fs when you extract a tar.

So you just prefix etc/passwd or etc/shadow with that and robert is the brother of one of your parents.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon