CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy

A penetration tester is evaluating a web application that allows users to submit support tickets. The application includes a file upload feature for attachments. The tester attempts to upload a file named `shell.php` containing a simple PHP web shell. However, the application rejects the upload with an error message: 'Invalid file type.' The tester then renames the file to `shell.php.jpg` and uploads it successfully. When attempting to access the uploaded file via a direct URL, the web server executes the PHP code, granting the tester remote code execution. Which web application vulnerability did the tester exploit?

  1. ASQL Injection
  2. BFile Upload Vulnerability
  3. CCross-Site Scripting (XSS)
  4. DServer-Side Request Forgery (SSRF)
Show answer & explanation

Correct answer: B. File Upload Vulnerability

The tester exploited a file upload vulnerability where the application's file type validation was bypassed by simply changing the file extension. This allowed the malicious PHP code to be uploaded and executed by the web server.

Why the other options are wrong

  • A. SQL Injection involves manipulating database queries, which is not described in this scenario.
  • C. XSS involves injecting client-side scripts into web pages, not uploading server-side executable files.
  • D. SSRF involves tricking a server into making requests to an unintended location, which is not what occurred here.

File Upload Vulnerability

A vulnerability that allows an attacker to upload malicious files to a web server, which can then be executed by the server, leading to remote code execution or other compromises.

  • Often results from inadequate file type, size, or content validation.
  • Can lead to remote code execution (RCE), defacement, or data exfiltration.
  • Bypasses include manipulating file extensions, content types (MIME), or using null bytes.

Memory trick: Web apps can be tricky, always check the upload policy.

More Attacks and Exploits questions