SegAudit
Trust center

Untrusted input

How hostile configs, logs and engagement files are handled.

Every file you load is treated as hostile data.

  • XML. Parsed with DOMParser, never innerHTML. Documents containing <!DOCTYPE> or <!ENTITY> are rejected before parsing, so XML external entity and billion-laughs attacks cannot expand.
  • Size caps. Byte, element and row ceilings: 32 MB of XML, 64 MB of CSV, 250,000 rows. Larger files are not read.
  • CSV. Rows are split, never executed. Object names are escaped in generated CLI.
  • FortiOS files. Configuration backups and FortiGate or FortiAnalyzer logs are read as text under the same caps. A compressed log from the FortiGate CLI is unpacked with an output cap, so a crafted file cannot expand without limit. Encrypted backups are refused.
  • Cisco ASA files. A show running-config capture and syslog exports are read as text under the same caps. Banners, prompts and lines that are not configuration or ASA log messages are skipped, never run.
  • Cisco FTD files. The FMC export is JSON, parsed as data under the same caps, and FTD connection-event syslog is read as text. Nothing in either file is run.
  • Check Point files. The Check Point export is JSON, parsed as data under the same caps, and the firewall logs are read as text (syslog, CEF or a SmartConsole CSV). Nothing in either file is run.
  • Spreadsheet exports. Cells starting with =, +, -, @, tab or carriage return are prefixed with ', so a hostile rule, zone or object name cannot run as a formula.
  • Saved engagements. Loading one goes through the same parser caps and field validation as any other untrusted JSON, including observations and finding edits. An encrypted file is authenticated by AES-GCM before it is parsed, so a tampered file is rejected.
  • Firm profiles. A firm file is validated field by field; the logo must be a PNG or JPEG of at most 256 KB whose header is checked.
  • Word documents. Text from the config, logs and your own notes is escaped as XML, and characters Word cannot hold are dropped.
  • Chain of custody. The SHA-256 of each source file is computed in the browser and printed on the report.

Last updated 2026-10-02.