Test filesImages › fake-jpeg-is-executable.jpg

Sample JPEG file

A file named .jpg whose magic bytes are the DOS/PE "MZ" signature. Contains no executable code - just the header and filler.

↓ Download fake-jpeg-is-executable.jpg
Filenamefake-jpeg-is-executable.jpg
FormatJPEG (spoofed)
Size2.1 KB (2,131 bytes)
MIME typeimage/jpeg
SHA-2564ba83fec93b79c99a1d2f2be5e10620d7ca634766d5a783a8d9a7a19c47d610f
What this file catchesUpload validation that trusts the file extension or the client-supplied Content-Type instead of sniffing actual magic bytes. This is the number one file-upload bypass.

Download & verify

curl -fsSL -o "fake-jpeg-is-executable.jpg" "https://files.hexaqa.com/image/fake-jpeg-is-executable.jpg"
curl -fsSL "https://files.hexaqa.com/image/fake-jpeg-is-executable.jpg" | sha256sum # expect: 4ba83fec93b79c99a1d2f2be5e10620d7ca634766d5a783a8d9a7a19c47d610f

More images test files

bmp-24bit.bmpfavicon.icogif-animated.gifgif-static.gifjpeg-baseline.jpgjpeg-tiny-16px.jpgno-extensionpng-1x1.png

← All Images files