<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Soroush Dalili - Computer Security Is My Interest! &#187; file uploader bypass methods</title>
	<atom:link href="http://soroush.secproject.com/blog/tag/file-uploader-bypass-methods/feed/" rel="self" type="application/rss+xml" />
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili&#039;s blog - بلاگ سروش دلیلی</description>
	<lastBuildDate>Tue, 10 Jan 2012 22:54:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Improve File Uploaders’ Protections &#8211; Bypass Methods- Rev. 1.0</title>
		<link>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/</link>
		<comments>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 23:59:35 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[fckeditor bypass methods]]></category>
		<category><![CDATA[file uploader bypass methods]]></category>
		<category><![CDATA[file uploader security bypass]]></category>
		<category><![CDATA[file uploader security improvement]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=232</guid>
		<description><![CDATA[Some new methods of bypassing file uploaders protections have been discussed. As an example bypassing by using: trailing spaces and dots, “::$data.”, direct Null char, IIS semi-colon  bug, and so on. Uploading files by using web applications is very common. However, there is always a high risk around this matter. In case of uploading a [...]]]></description>
			<content:encoded><![CDATA[<blockquote>
<p style="text-align: justify;"><span style="color: #ff0000;"><span style="color: #000000;">Some new methods of bypassing file uploaders protections have been discussed. As an example bypassing by using:<strong> </strong></span><span style="color: #000000;"><strong>trailing spaces and dots, </strong><strong>“::$data.”, </strong><strong>direct Null char, IIS semi-colon  bug,</strong> and so on.</span></span></p>
</blockquote>
<p style="text-align: justify;">Uploading files by using web applications is very common. However, there is always a high risk around this matter. In case of uploading a web-shell file which can be absolutely malicious, an attacker can get the same privilege of access as the web application to the server. In this paper, which is mostly around the Windows-based web applications, some general solutions for protecting against this type of attack have been suggested. Moreover, as a proof of concept, some of the most general protection methods and the way of bypassing them have been discussed.</p>
<p style="text-align: justify;">This article is an educational article to improve the security of the web applications. And, the author of this article (“Soroush Dalili”) does not accept and has no responsibility about the content or usage of this article in any other way. Any other usage of this article except the legal ones is completely prohibited.</p>
<p style="text-align: justify;">Please respect the copyright and mention the name of the author (“Soroush Dalili”) in case of using this article.</p>
<p style="text-align: left;"><a title="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" href="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" target="_blank"><strong>Download</strong> this article by clicking here.</a> (<a title="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" href="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" target="_blank">http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf</a>)</p>
<p style="text-align: justify;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

