Download as pdf or txt
Download as pdf or txt
You are on page 1of 6

Web

 Applica+on  Pentes+ng  

Vivek  Ramachandran  
SWSE,  SMFE,  SPSE,  SISE,  SLAE,  SGDE  Course  Instructor  

Cer+fica+ons:                          hGp://www.securitytube-­‐training.com    
 
Pentester  Academy:    hGp://www.PentesterAcademy.com    

©SecurityTube.net  
File  Upload  Vulnerability  Basics  

©SecurityTube.net  
File  Upload  Vulnerability  

•  AGacker  abuses  a  file  upload  feature  to  


upload  malicious  script  

•  Script  is  executed  and  allows  for  further  


aGacks  
–  webshell  

•  Filters  based  on  Content-­‐Type,  Extension  


names,  Size  etc.    

©SecurityTube.net  
Arbitrary  File  Upload  Vulnerable  ISO  

securitytube:123321  

©SecurityTube.net  
Download  

•  hGps://sourceforge.net/projects/
arbitraryfileuploados  
–  user:pass  =  securitytube:123321  

•  created  by  Ashish  Bhangale  

•  Bugs  and  Issues:  


–  ashish@binarysecuritysolu+ons.com    

©SecurityTube.net  
Pentester  Academy  

©SecurityTube.net  

You might also like