INSECURE FILE UPLOAD VULNERABILITY
&
SECURITY MEASURES
Kunwar Atul
Agenda
Whoami
What is file upload vulnerability????
How http file upload works????
Demo
References
#whoami
Kunwar Atul
Pentester(Web/Network/Mobile)
Security Enthusiast | Learner
Ultra N00b in Hardware Hacking
Blogger (kunwar-atul-hax0r.blogspot.in)
Bug Hunter
What is file upload vulnerability????
How http file upload works????
How http file upload works????
<form action="uploader.php" method="post" enctype="multipart/form-data">
Select File:
<input type="file" name="fileToUpload"/>
<input type="submit" value="Upload Image" name="submit"/>
</form>
Demo
References
1. https://pentestlab.blog/2012/11/29/bypassing-file-upload-restrictions/amp/
2. http://www.hackingarticles.in/5-ways-file-upload-vulnerability-exploitation/
3. https://www.sans.org/reading-room/whitepapers/testing/web-application-file-
upload-vulnerabilities-36487
4. https://www.sans.org/reading-room/whitepapers/testing/web-application-file-
upload-vulnerabilities-36487
Wake Up It’s Over
Find me here
Facebook : https://www.facebook.com/kunwaratulhax0r
Twitter : https://twitter.com/kunwaratulhax0r

Insecure file upload vulnerability