We covered a basic example of bypassing file upload filters by changing the extension. We used Burp Suite to intercept the POST request and changed the extension to the desired one. The vulnerability was caused by the lack of input filters after the file has been uploaded. This was part of OverTheWire Natas Level 12 challenge.

Obtenir les notes du certificat OSCP

Next Level Password:

YWqo0pjpcXzSIl5NMAVxg12QxeC1w9QG

Vidéo pas à pas

A propos de l'Auteur

Instructeur et nageur en cybersécurité

Voir les Articles