#21 File hosting

开启中
sindre5 年前创建 · 0 条评论
sindre 评论于 5 年前

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.

Although not an OWASP v4 code, File Hosting is a major part of modern intelligent threat actors. If your server hosts files instead of just letting users download them they can be used as part of spear-phishing attacks or as part of reconnaissance. This webpage should default to always downloading a file, even if accessed directly, or alternatively, deny access if a file is access directly.
sindre 5 年前 添加了里程碑 Optional vulnerabilities
sindre 添加了标签
webpy
5 年前
sindre 添加了标签
bug
5 年前
sindre 添加了标签
security misconfiguration
5 年前
sindre 5 年前 修改了里程碑从 Optional vulnerabilitiesRequired fixes
sindre 5 年前 修改了里程碑从 Required fixesOptional vulnerabilities
登陆 并参与到对话中。
正在加载...
取消
保存
这个人很懒,什么都没留下。