← Notes

What a safe extractor checks before it unpacks

An archive is a set of instructions for writing files to your disk, and a malicious one can write them somewhere you did not choose or fill the disk entirely. Here are the tricks, and the checks that stop them.

Opening an archive feels passive, like opening a document. It is not. An archive is a list of instructions — create this file, at this path, with these contents — and the extractor carries them out on your disk.

Most archives are exactly what they appear to be. But the format allows instructions you would never agree to if you read them, and a careful extractor checks for them before writing anything.

Path traversal: writing outside the folder

Every entry in a ZIP has a path, like photos/beach.jpg. The extractor joins that to the destination folder and writes the file there.

Now imagine an entry called ../../Library/LaunchAgents/something.plist. Joined naïvely to ~/Downloads/archive/, the .. segments climb out of the destination and the file lands somewhere else entirely — in this example, somewhere that runs programs at login.

This class of problem was widely publicised in 2018 as Zip Slip, when researchers found it in a long list of libraries across many languages. Absolute paths such as /etc/something are the same trick in a more direct form.

The check: resolve every entry's final path before writing, and refuse any that would land outside the destination.

Symbolic links: the indirect route

Archive formats can store symbolic links — entries that point at another location. A malicious archive can include a link called docs pointing at a sensitive folder, followed by an ordinary-looking entry docs/file.txt. The second entry now writes through the link, outside the destination, without any .. in its name.

The check: refuse links that point outside the destination, or treat links with suspicion altogether, and never write through a link created earlier in the same extraction.

Zip bombs: small file, enormous result

Compression works by describing repetition compactly. A file consisting of one byte repeated billions of times compresses to almost nothing. An archive can therefore be a few kilobytes on disk and expand to terabytes.

The famous example, 42.zip, is 42 kilobytes and expands to about 4.5 petabytes through nested archives. More recent designs, published in 2019, reach huge ratios in a single layer by making many entries overlap the same compressed data. The goal is not to steal anything but to fill your disk or exhaust memory, which can crash apps or leave a machine unusable until the files are found and deleted.

The checks:

  • Compare the declared uncompressed size with the compressed size. Legitimate data rarely compresses by more than a few hundred to one; a thousand-to-one ratio deserves a warning.
  • Cap the total size and the number of files in one job.
  • Count what is actually written, not only what the archive claims, because the header can lie.

Running out of space halfway

Not every problem is malicious. A 10 GB archive of text can expand to 60 GB. If there is not room, the extraction fails part-way and leaves you with an incomplete folder that looks finished.

The check: compare the total uncompressed size with available disk space before starting.

Overwriting what is already there

An archive containing report.pdf, extracted into a folder that already has report.pdf, has to do something. Silently replacing it is the worst option.

The check: decide the policy before extraction starts — skip, keep both, or replace — rather than discovering the outcome afterwards.

What macOS does for you

macOS adds real protections around this. Downloaded files carry a quarantine flag, Gatekeeper checks apps that come out of archives before they first run, and sandboxed apps cannot write outside the locations you have granted them. Those limit the damage of a hostile archive considerably.

But the built-in Archive Utility is designed to be quick rather than inquisitive. It shows no warning about a suspicious ratio, and gives no summary of what an archive intends to do before it does it.

Habits worth having

  • Look inside before you extract. unzip -l file.zip lists entries without writing anything; long runs of ../ or absolute paths are a clear sign to stop.
  • Extract into a new, empty folder rather than straight into Downloads or your home folder.
  • Be suspicious of a small archive that claims to contain very large files.
  • Treat any app that emerges from an archive as a download in its own right.

What Ziploom does

Ziploom is an archive utility for Apple silicon Macs, and its checks happen before files are installed at the destination rather than after something has gone wrong. They cover:

  • unsafe paths, including traversal outside the destination,
  • symbolic links,
  • suspicious compression ratios,
  • oversized extraction jobs,
  • available disk space.

You choose in advance how existing destinations are handled, follow progress, and reveal the result in Finder. It extracts RAR, ZIP and 7Z, with optional password support, and creates ZIP and 7Z.

All processing stays on your Mac, with no accounts, analytics, advertising, telemetry or network features.

Keep reading