EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard
A web application allows users to upload profile pictures. A security engineer notices that the application checks the `Content-Type` header (e.g., `image/jpeg`) on the client-side but does not perform server-side validation of the file's actual content. An attacker could potentially bypass this control by uploading a malicious script file with a faked `Content-Type` header. Which countermeasure is most effective in preventing this type of attack?
- ADisabling directory listing on the upload folder.
- BPerforming server-side content validation (e.g., magic byte check) and whitelisting allowed extensions.
- CRenaming all uploaded files to a generic name like `image.jpg`.
- DEnforcing a strict file size limit for uploaded images.
Show answer & explanationAnswer & explanation
Correct answer: B. Performing server-side content validation (e.g., magic byte check) and whitelisting allowed extensions.
Client-side validation of `Content-Type` headers is easily bypassed. The most effective countermeasure is to perform robust server-side validation. This includes checking the file's 'magic bytes' to confirm its true file type (content validation), whitelisting only allowed file extensions, and ensuring the file is stored in a non-executable directory.
Why the other options are wrong
- A. Disabling directory listing prevents reconnaissance but does not stop a malicious file from being uploaded and potentially executed if it bypasses other checks.
- C. Renaming files prevents path traversal but doesn't stop a malicious script from being executed if the server processes it as such.
- D. File size limits prevent large uploads but not malicious content in smaller files.
Secure File Uploads
A set of security measures to prevent malicious files from being uploaded and executed on a web server.
- Always perform server-side validation.
- Validate file type (magic bytes), extension, and size.
- Store uploaded files in non-executable directories.
- Rename files to prevent path traversal and ensure unique names.
Memory trick: Uploads need a 'Magic Whitelist' on the server.