Prevention
Extension Validation
- whitelist and blacklists
- back-end and front end validation
Content validation
- validate both the File Signature and the HTTP Content-Type header
Upload Disclosure
- avoid disclosing the uploads directory or providing direct access to the uploaded file
- https://enterprise.hackthebox.com/academy-lab/30000/2125/modules/136/1309