We covered a basic example of bypassing file upload filters by changing the extension. We used Burp Suite to intercept the POST request and changed the extension to the desired one. The vulnerability was caused by the lack of input filters after the file has been uploaded. This was part of OverTheWire Natas Level 12 challenge.

Get OSCP Certificate Notes

Next Level Password:

YWqo0pjpcXzSIl5NMAVxg12QxeC1w9QG

Video Walkthrough

About the Author

Cybersecurity Instructor & Swimmer

View Articles