Skip to content

Prevention

Extension Validation

  • whitelist and blacklists
  • back-end and front end validation

Content validation

  • validate both the File Signature and the HTTP Content-Type header

Upload Disclosure

  • avoid disclosing the uploads directory or providing direct access to the uploaded file
  • https://enterprise.hackthebox.com/academy-lab/30000/2125/modules/136/1309