<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[(doyensec.com) Weaponizing NASA&#x27;s CFITSIO Extended Filename Syntax: How Legacy Features Become Attack Surfaces]]></title><description><![CDATA[<p>(doyensec.com) Weaponizing NASA's CFITSIO Extended Filename Syntax: How Legacy Features Become Attack Surfaces</p><p>New research exposes how NASA’s CFITSIO Extended Filename Syntax (EFS) can be weaponized for arbitrary file copy, SSRF, HTTP header injection, and local file exfiltration. Legacy features in scientific tooling pose evolving risks when threat models shift.</p><p>In brief - CFITSIO’s EFS, designed for flexible file handling, enables critical attack primitives due to insufficient input sanitization and backward compatibility constraints. Mitigations like opt-in EFS and stricter validation are recommended.</p><p>Technically - Exploits leverage EFS clauses (e.g., `outfile`, `http://`, `root://[b...]`) to copy `/etc/passwd`, force downloads, inject HTTP headers via newlines, and reinterpret files as FITS data for exfiltration. Some apps (e.g., Siril) mitigate risks via literal file opens, but security was not the primary driver. Complexity arises from CFITSIO’s design and compatibility requirements.</p><p>Source: <a href="https://blog.doyensec.com/2026/05/19/cfitsio-weaponized-filenames.html" rel="nofollow noopener"><span>https://</span><span>blog.doyensec.com/2026/05/19/c</span><span>fitsio-weaponized-filenames.html</span></a></p><p><a href="https://swecyb.com/tags/Cybersecurity" rel="tag">#<span>Cybersecurity</span></a> <a href="https://swecyb.com/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/3d4cf3e3-720e-4309-b293-30361aed5e13/doyensec.com-weaponizing-nasa-s-cfitsio-extended-filename-syntax-how-legacy-features-become-attack-surfaces</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 12:12:17 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3d4cf3e3-720e-4309-b293-30361aed5e13.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 19 May 2026 10:48:00 GMT</pubDate><ttl>60</ttl></channel></rss>