CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester discovers a web application that allows users to upload profile pictures. Upon uploading a file named `image.php.jpg`, the server processes it and saves it as `image.php.jpg` in a publicly accessible directory. When the tester navigates to the URL of the uploaded file, a 'PHP code execution' error is displayed. Which web application attack is MOST likely indicated by this behavior?
- AServer-Side Request Forgery (SSRF)
- BFile Upload Vulnerability
- CSQL Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. File Upload Vulnerability
The ability to upload a file with a `.php` extension (even if disguised with `.jpg`) and then trigger PHP code execution (indicated by the error) is a clear sign of a file upload vulnerability. This allows an attacker to bypass file type restrictions and execute arbitrary code on the server.
Why the other options are wrong
- A. SSRF involves the server making requests, not executing uploaded code.
- C. SQL Injection targets databases, not file uploads leading to code execution.
- D. XSS involves injecting client-side scripts, not server-side code execution via file upload.
File Upload Vulnerability
A security flaw in a web application that allows an attacker to upload malicious files (e.g., web shells, scripts) to the server, potentially leading to remote code execution, defacement, or other compromise.
- Occurs due to insufficient validation of file types, content, or size.
- Can be exploited by uploading files with double extensions (e.g., .php.jpg) or content type manipulation.
- Often leads to Remote Code Execution (RCE) if the uploaded file is executed by the server.
Memory trick: Uploads unchecked, code executes, server wrecked.