File Upload Vulnerabilities
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
File uploads are an easy way for an attacker to inject malicious code into your application.
- Prevalence
- Common
- Exploitability
- Moderate
- Impact
- Harmful
What is a file upload vulnerability?
A file upload vulnerability is a code injection weakness in which an application accepts files without validating their type, contents, name or size, then stores them where they can be executed. Attackers exploit it by uploading a script disguised as a harmless file, such as an image, then requesting it to run code on the server.
What you'll learn
- Why client-side file type checks do not stop a malicious upload
- How an uploaded script becomes a web shell on your server
- How to store, rename and validate uploads so they cannot be executed
Where this lesson counts
OWASP Top 10
Missing threat modelling and security requirements leave flaws no amount of careful coding can fix.
Learn more about A06PCI DSS 4.0
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Learn more about 6.2.4This lesson includes
-
File Upload Vulnerabilities lab
Mal finds a profile image upload that checks file types only in JavaScript. Watch him disable JavaScript, upload a PHP web shell and run it from its public URL. Then take over: pass commands through the shell to find and read the database config file.
-
How to prevent File Upload Vulnerabilities
The prevention guide covers six approaches:
- Segregate Your Uploads
- Ensure Upload Files Cannot Be Executed
- Rename Files on Upload
- Validate File Formats and Extensions
- Validate the Content-Type Header
- Use a Virus Scanner
-
File Upload Vulnerabilities quiz
Two questions. Passing marks the lesson complete.
Sources
- An Introduction to Web-shells Acunetix
- Unrestricted File Upload Vulnerabilities OWASP
- File Upload Vulnerabilities PortSwigger
- File Upload Cheatsheet OWASP
Related lessons
Browse all 45 lessons
Directory Traversal
Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.
Command Execution
If your application calls out to the OS, you need to be sure command strings are securely constructed.
Remote Code Execution
If an attacker can smuggle code into your web-server process, you have a serious problem.
Cross-Site Scripting
If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.