#21 File hosting

Ouvert
créé il y a 5 ans par sindre · 0 commentaires
sindre a commenté il y a 5 ans

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.
sindre a ajouté cela au jalon Optional vulnerabilities il y a 5 ans
sindre a ajouté l'étiquette
webpy
il y a 5 ans
sindre a ajouté l'étiquette
bug
il y a 5 ans
sindre a ajouté l'étiquette
security misconfiguration
il y a 5 ans
sindre a modifié le jalon de Optional vulnerabilities à Required fixes il y a 5 ans
sindre a modifié le jalon de Required fixes à Optional vulnerabilities il y a 5 ans
Connectez-vous pour rejoindre cette conversation.
Chargement…
Annuler
Enregistrer
Il n'existe pas encore de contenu.