#21 File hosting

Open
5 jaren geleden werd geopend door sindre · 0 opmerkingen

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.
sindre added this to the Optional vulnerabilities milestone 5 jaren geleden
sindre added the
webpy
label 5 jaren geleden
sindre added the
bug
label 5 jaren geleden
sindre added the
security misconfiguration
label 5 jaren geleden
sindre mijlpaal bewerkt van Optional vulnerabilities Required fixes 5 jaren geleden
sindre mijlpaal bewerkt van Required fixes Optional vulnerabilities 5 jaren geleden
Log in om deel te nemen aan deze discussie.
Laden…
Annuleren
Opslaan
Er is nog geen inhoud.