How File Upload Vulnerabilities Work!

Поділитися
Вставка
  • Опубліковано 23 сер 2024

КОМЕНТАРІ • 54

  • @nathangriffiths8809
    @nathangriffiths8809 2 роки тому +7

    Thank you Intigriti. I find these short videos easy to understand and extremely helpful for my learning.

    • @intigriti
      @intigriti  2 роки тому

      Glad you like them! Going over all our videos should give you a solid base!
      And there is more to come every week :)

  • @asaad0x
    @asaad0x 2 роки тому +1

    This was very smooth ! ❤️ Your tune of voice can make watch all of the channel videos without any issues 😁❤️ what a great content and great people you are intigriti ❤️ Love here from Egypt 😁❤️

    • @intigriti
      @intigriti  2 роки тому +1

      Thank you so much. We are glad the videos are easy to understand ❤️ We appreciate it that you are watching our videos!

  • @havefun4035
    @havefun4035 2 роки тому +2

    that's is an amazing video man, I have been trying to solve this lab for over two weeks now. And I finally DID IT !!!!!

    • @intigriti
      @intigriti  2 роки тому +1

      We are really happy to hear that our videos are helping the community ❤️. And congrats on solving it! Make sure to check out our other videos as well if you need help!

  • @C0ldSpace
    @C0ldSpace 4 місяці тому

    Bro thank you so much. As a beginner, I had no clue what any of this meant. I’m subbing.

    • @intigriti
      @intigriti  4 місяці тому

      Glad it could help and thanks for the sub! 🥰

  • @rajanrawal6396
    @rajanrawal6396 2 роки тому +2

    amazing, we need such playlist more and more in the future

    • @intigriti
      @intigriti  2 роки тому

      The more people that subscribe and watch our videos, the more videos we can make!

  • @nishantdalvi9470
    @nishantdalvi9470 7 місяців тому

    Thanks you Intigriti for providing such a quality content free of cost

    • @intigriti
      @intigriti  7 місяців тому

      It's our pleasure! 💜

  • @mosesroy2813
    @mosesroy2813 2 роки тому +1

    the best channel to learn ethical hacking...very easy to understand

    • @intigriti
      @intigriti  2 роки тому

      Thank you so much Moses 😇 We really appreciate it. Share the word!

  • @nokotable
    @nokotable Рік тому +1

    you did justice to this lab. please what is the best solution to such an attack, does that mean if I upload a dot PHP file from the frontend (webb form) of the application it will still go through. without verifying the file extension?

    • @intigriti
      @intigriti  Рік тому

      Thank you! If I understand your question correctly, you want to know the best ways to prevent a file upload attack? There's a few common ones:
      - Blacklist dangerous extensions (in fact, it's much more secure to whitelist safe extensions)
      - Check the content-type of files being uploaded (sure, it has a .jpg extension, but is the content type PHP?)
      - Scan the file (does the file signature match the extension? a .jpg file should have a signature like "ÿØÿà")

  • @steiner254
    @steiner254 2 роки тому +2

    Honestly This Is Interesting.. Keep Pushing... Regards,Steiner254.

    • @intigriti
      @intigriti  2 роки тому +1

      Thanks Alvin 💪 We will keep pushing for sure!

  • @0xgodson119
    @0xgodson119 2 роки тому

    Hey bro. Really you r speaking Very Slowly and softly. I

    • @intigriti
      @intigriti  2 роки тому

      Thank you so much 😀 We want to be accessible to every person, not just native speakers. So, we are trying our best!

  • @noormohammadgagguturi
    @noormohammadgagguturi 2 роки тому

    Crystal Clear Explanation Thank You

    • @intigriti
      @intigriti  2 роки тому

      Glad you liked it 😇

  • @terabaap1719
    @terabaap1719 2 роки тому

    Well Explained brother ..... thanks you !!!

  • @houba1263
    @houba1263 2 місяці тому

    Hello in this is the content of the file is saved in the db or the file is saved in the filesystem?

    • @intigriti
      @intigriti  2 місяці тому

      It would be on the filesystem!

  • @dizonnicolefranza.4181
    @dizonnicolefranza.4181 2 роки тому

    thanks, may I suggest next vid is upload file leads to xss

    • @intigriti
      @intigriti  2 роки тому

      Great suggestion! We will look into that one 😇

  • @samexter
    @samexter 2 роки тому

    Does this lab restrict the codes that can be executed? Is only the get_file_content be used?

    • @intigriti
      @intigriti  2 роки тому +1

      Yeah, the labs always have a clear goal for you in mind! If you read the lab's description, it becomes clear what you need to achieve!

  • @VDenys
    @VDenys 3 місяці тому

    I did everything correctly, sequentially, but in my Show File - Response - Content Length: 0 ...

    • @intigriti
      @intigriti  2 місяці тому

      Hey, did you manage to solve it? If not, it might be worth double-checking the steps in the official portswigger solution

  • @newbiejember9854
    @newbiejember9854 Рік тому +1

    wow thats cool... amazin video

  • @Safvanviber-xm3pn
    @Safvanviber-xm3pn 8 місяців тому

    Love from kerala❤

  • @masthanjinostra2981
    @masthanjinostra2981 2 роки тому +1

    Bypassing security techniques for this ..

    • @intigriti
      @intigriti  2 роки тому

      Can you elaborate further?

  • @messiah44
    @messiah44 2 роки тому

    Thank U Inti!

    • @intigriti
      @intigriti  2 роки тому

      You are welcome 😇
      PS: It's called Intigriti 🤪

  • @Lapiduse
    @Lapiduse 7 місяців тому

    I can't stop going through the labs, that's it very addictive)))
    Thanks!

    • @intigriti
      @intigriti  7 місяців тому +1

      There are far worse things to be addicted to 😉

    • @firzainsanudzaky739
      @firzainsanudzaky739 7 місяців тому

      @@intigriti this task cant be access for me..., it says eror on the access lab

  • @jaibalajibalaji4934
    @jaibalajibalaji4934 2 роки тому +1

    love intigriti from india

    • @intigriti
      @intigriti  2 роки тому +2

      Love back from Belgium!

  • @zeropixell3152
    @zeropixell3152 2 роки тому

    Great ❤️❤️❤️

  • @rehxn21
    @rehxn21 Рік тому

    but wait where this carlos came from like i dont get that part why only carlos why not john mike eddy

  • @mrrahim5622
    @mrrahim5622 2 роки тому +2

    1st

  • @KushChoudhary
    @KushChoudhary 2 роки тому +1

    Didn't explain the most important part 'why the code gets executed' and 'why does content-type not able to mitigate this'. One word: Disappointed.

    • @intigriti
      @intigriti  2 роки тому

      More details can be found in our Hackademy which is directly linked below in the description! 😇

    • @KushChoudhary
      @KushChoudhary 2 роки тому

      @@intigriti Thanks!