Sample files for testing file uploads
An upload form decides three things about every file: whether it is too big, whether it is what it claims to be, and whether the code behind the form can process it. Each file below sits on the edge of one of those decisions. Every one has a stable URL, so a test can fetch it instead of committing it.
Size limits
https://loremfile.dev/bin/10mb-minus-1.bin · 10 MB (9,999,999 bytes) · application/octet-stream
https://loremfile.dev/bin/10mb.bin · 10 MB (10,000,000 bytes) · application/octet-stream
https://loremfile.dev/bin/10mb-plus-1.bin · 10 MB (10,000,001 bytes) · application/octet-stream
One byte under, exactly on, and one byte over 10 MB in decimal units. A limit of 10,000,000
bytes accepts the first and refuses the last; the middle file shows whether the limit is
inclusive, which is the byte a check written with > instead of >= gets wrong.
https://loremfile.dev/bin/10mib-plus-1.bin · 10.5 MB (10,485,761 bytes) · application/octet-stream
The same boundary in binary units. If bin/10mb-plus-1.bin was accepted, the limit is
counting in MiB, and this is the file it should refuse.
https://loremfile.dev/edge/zero-byte.pdf · 0 bytes · application/pdf · must-fail
An empty file served as application/pdf. A form that checks the type but not the length
hands it to a PDF library, which then fails somewhere less helpful than the upload step.
https://loremfile.dev/pdf/10mb.pdf · 9.9 MB (9,924,917 bytes) · application/pdf
A document whose size cannot be squeezed: every page embeds a noise image, so a client or proxy that compresses uploads does not bring it under a limit by accident.
What the file really is
https://loremfile.dev/edge/pdf-with-png-extension.png · 1.8 KB (1,795 bytes) · image/png · varies
A PDF under a .png name, served as image/png. A check that trusts the extension or the
Content-Type header calls it an image; one that reads the first bytes finds a PDF signature.
https://loremfile.dev/edge/pdf-zip-polyglot.pdf · 800 bytes · application/pdf · varies
A valid PDF and a valid zip archive in the same bytes. Magic-byte sniffing calls it a PDF, and anything that later unpacks archives finds a file inside. Some scanners refuse polyglots outright, so decide what your form does with one rather than finding out.
https://loremfile.dev/heic/640x480.heic · 5.1 KB (5,066 bytes) · image/heic · 640x480 · RGB
HEIC, the format iPhones capture photos in. A form that previews uploads in the browser has to convert it or show a placeholder, because not every browser displays HEIC.
Images that change when decoded
https://loremfile.dev/jpg/exif-orientation-8-640x480.jpg · 16 KB (16,011 bytes) · image/jpeg · 480x640 · RGB
The pixels are stored rotated, with an EXIF tag that says how to turn them upright. A thumbnailer that strips metadata without applying the tag publishes the card sideways.
https://loremfile.dev/jpg/cmyk-640x480.jpg · 25.3 KB (25,267 bytes) · image/jpeg · 640x640 · CMYK
CMYK rather than RGB. Image code that assumes three channels either rejects it or produces the wrong colours. Despite its name it measures 640x640, as the line above shows.
https://loremfile.dev/jpg/4000x3000.jpg · 279.2 KB (279,204 bytes) · image/jpeg · 4000x3000 · RGB
Twelve megapixels in under 300 KB. A resizer that decodes the whole image before scaling holds every one of those pixels in memory for a file that small, so limit pixels as well as bytes.
Archives
https://loremfile.dev/edge/zip-directory-traversal-name.zip · 782 bytes · application/zip · varies
A readable zip with an entry named ../evil.txt. Code that extracts uploads by joining each
entry name to a target directory without checking it writes outside that directory.
https://loremfile.dev/zip/zip64-70000-empty-files.zip · 7.4 MB (7,420,098 bytes) · application/zip · 70,000 entries
More entries than a classic zip header can count, so it needs ZIP64. A server that limits uploads by entry count and reads only the classic two-byte count sees the wrong number.
https://loremfile.dev/zip/aes256-password-loremfile.zip · 2.1 KB (2,064 bytes) · application/zip · 3 entries
Encrypted with the password loremfile. A virus scanner or content check cannot look
inside, so the form needs a rule for archives it cannot inspect.
https://loremfile.dev/zip/empty.zip · 22 bytes · application/zip · 0 entries
A valid zip with nothing in it, which plenty of readers reject. Accept it or refuse it, but on purpose.
For why a broken file fails, and what each one's outcome means, see testing parsers and error handling.