#21 File hosting

Öppen
öppnade 5 år sedan av sindre · 0 kommentarer
sindre kommenterad 5 år sedan

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.
sindre lade till denna till milstolpe Optional vulnerabilities 5 år sedan
sindre added the
webpy
label 5 år sedan
sindre added the
bug
label 5 år sedan
sindre added the
security misconfiguration
label 5 år sedan
sindre modifierade milstolpen från Optional vulnerabilities till Required fixes 5 år sedan
sindre modifierade milstolpen från Required fixes till Optional vulnerabilities 5 år sedan
Logga in för att delta i denna konversation.
Laddar…
Avbryt
Spara
Det finns inget innehåll än.