Sample files for testing file uploads

An upload form decides three things about every file: whether it is too big, whether it is what it claims to be, and whether the code behind the form can process it. Each file below sits on the edge of one of those decisions. Every one has a stable URL, so a test can fetch it instead of committing it.

Size limits

https://loremfile.dev/bin/10mb-minus-1.bin · 10 MB (9,999,999 bytes) · application/octet-stream

https://loremfile.dev/bin/10mb.bin · 10 MB (10,000,000 bytes) · application/octet-stream

https://loremfile.dev/bin/10mb-plus-1.bin · 10 MB (10,000,001 bytes) · application/octet-stream

One byte under, exactly on, and one byte over 10 MB in decimal units. A limit of 10,000,000 bytes accepts the first and refuses the last; the middle file shows whether the limit is inclusive, which is the byte a check written with > instead of >= gets wrong.

https://loremfile.dev/bin/10mib-plus-1.bin · 10.5 MB (10,485,761 bytes) · application/octet-stream

The same boundary in binary units. If bin/10mb-plus-1.bin was accepted, the limit is counting in MiB, and this is the file it should refuse.

https://loremfile.dev/edge/zero-byte.pdf · 0 bytes · application/pdf · must-fail

An empty file served as application/pdf. A form that checks the type but not the length hands it to a PDF library, which then fails somewhere less helpful than the upload step.

https://loremfile.dev/pdf/10mb.pdf · 9.9 MB (9,924,917 bytes) · application/pdf

A document whose size cannot be squeezed: every page embeds a noise image, so a client or proxy that compresses uploads does not bring it under a limit by accident.

What the file really is

https://loremfile.dev/edge/pdf-with-png-extension.png · 1.8 KB (1,795 bytes) · image/png · varies

A PDF under a .png name, served as image/png. A check that trusts the extension or the Content-Type header calls it an image; one that reads the first bytes finds a PDF signature.

https://loremfile.dev/edge/pdf-zip-polyglot.pdf · 800 bytes · application/pdf · varies

A valid PDF and a valid zip archive in the same bytes. Magic-byte sniffing calls it a PDF, and anything that later unpacks archives finds a file inside. Some scanners refuse polyglots outright, so decide what your form does with one rather than finding out.

https://loremfile.dev/heic/640x480.heic · 5.1 KB (5,066 bytes) · image/heic · 640x480 · RGB

HEIC, the format iPhones capture photos in. A form that previews uploads in the browser has to convert it or show a placeholder, because not every browser displays HEIC.

Images that change when decoded

https://loremfile.dev/jpg/exif-orientation-8-640x480.jpg · 16 KB (16,011 bytes) · image/jpeg · 480x640 · RGB

The pixels are stored rotated, with an EXIF tag that says how to turn them upright. A thumbnailer that strips metadata without applying the tag publishes the card sideways.

https://loremfile.dev/jpg/cmyk-640x480.jpg · 25.3 KB (25,267 bytes) · image/jpeg · 640x640 · CMYK

CMYK rather than RGB. Image code that assumes three channels either rejects it or produces the wrong colours. Despite its name it measures 640x640, as the line above shows.

https://loremfile.dev/jpg/4000x3000.jpg · 279.2 KB (279,204 bytes) · image/jpeg · 4000x3000 · RGB

Twelve megapixels in under 300 KB. A resizer that decodes the whole image before scaling holds every one of those pixels in memory for a file that small, so limit pixels as well as bytes.

Archives

https://loremfile.dev/edge/zip-directory-traversal-name.zip · 782 bytes · application/zip · varies

A readable zip with an entry named ../evil.txt. Code that extracts uploads by joining each entry name to a target directory without checking it writes outside that directory.

https://loremfile.dev/zip/zip64-70000-empty-files.zip · 7.4 MB (7,420,098 bytes) · application/zip · 70,000 entries

More entries than a classic zip header can count, so it needs ZIP64. A server that limits uploads by entry count and reads only the classic two-byte count sees the wrong number.

https://loremfile.dev/zip/aes256-password-loremfile.zip · 2.1 KB (2,064 bytes) · application/zip · 3 entries

Encrypted with the password loremfile. A virus scanner or content check cannot look inside, so the form needs a rule for archives it cannot inspect.

https://loremfile.dev/zip/empty.zip · 22 bytes · application/zip · 0 entries

A valid zip with nothing in it, which plenty of readers reject. Accept it or refuse it, but on purpose.

For why a broken file fails, and what each one's outcome means, see testing parsers and error handling.