如何区分xlsx、docx与Zip压缩包?求无扩展名识别文件类型方案
Great question—this is a common gotcha with OpenXML formats (xlsx, docx, pptx) since they're technically zip archives under the hood, which is why file --b lumps them in with regular zips. Here are a few reliable, extension-agnostic ways to distinguish these office files from true executable/compressed files you want to block:
1. Inspect the zip archive's internal structure
OpenXML files have a strict required directory structure that regular zip archives won't have. You can check for the presence of core files/directories like [Content_Types].xml, _rels/, and docProps/ without fully extracting the file:
# Check if the archive contains key OOXML marker files unzip -l "$FILENAME" | grep -qE "(^\s*[0-9]+\s+[0-9-]+\s+[0-9:]+\s+(\[Content_Types\]\.xml|_rels/|docProps/))" # If exit code is 0, it's an OOXML file; 1 means it's a regular zip
This works because unzip -l only reads the archive's directory metadata, so it's fast even for large files.
2. Customize libmagic rules for the file command
The file tool uses libmagic under the hood, and you can create a custom magic file to add specific detection for OpenXML formats. Create a file named ooxml.magic with this content:
# Detect Microsoft OOXML (xlsx, docx, pptx, etc.) 0 string PK\x03\x04 >45 string [Content_Types].xml Microsoft OOXML document
Then use it with file to get accurate results:
file -m ooxml.magic --b "$FILENAME"
This will return "Microsoft OOXML document" for valid xlsx/docx files instead of the generic zip label. You can even add this to your system's global magic rules if you want it to apply everywhere.
3. Use specialized office file detection tools
If you're okay with installing additional packages, tools like ooxml-tools (available on Debian/Ubuntu via apt install ooxml-tools) include commands to validate and identify OpenXML files:
ooxmlinfo "$FILENAME"
This will explicitly tell you if the file is a valid OOXML document, along with metadata like creator and modification date.
All these methods rely on the actual file content rather than extensions, so they won't be fooled by renamed files. Just make sure to integrate them into your existing blocking workflow—for example, first run file --b to flag potential zips/executables, then run one of these checks to whitelist valid OOXML files before blocking.
内容的提问来源于stack exchange,提问作者Richa Sinha

