EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingHard

A web application allows users to upload profile pictures. A security engineer notices that the application checks the `Content-Type` header (e.g., `image/jpeg`) on the client-side but does not perform server-side validation of the file's actual content. An attacker could potentially bypass this control by uploading a malicious script file with a faked `Content-Type` header. Which countermeasure is most effective in preventing this type of attack?

  1. ADisabling directory listing on the upload folder.
  2. BPerforming server-side content validation (e.g., magic byte check) and whitelisting allowed extensions.
  3. CRenaming all uploaded files to a generic name like `image.jpg`.
  4. DEnforcing a strict file size limit for uploaded images.
Show answer & explanation

Correct answer: B. Performing server-side content validation (e.g., magic byte check) and whitelisting allowed extensions.

Client-side validation of `Content-Type` headers is easily bypassed. The most effective countermeasure is to perform robust server-side validation. This includes checking the file's 'magic bytes' to confirm its true file type (content validation), whitelisting only allowed file extensions, and ensuring the file is stored in a non-executable directory.

Why the other options are wrong

  • A. Disabling directory listing prevents reconnaissance but does not stop a malicious file from being uploaded and potentially executed if it bypasses other checks.
  • C. Renaming files prevents path traversal but doesn't stop a malicious script from being executed if the server processes it as such.
  • D. File size limits prevent large uploads but not malicious content in smaller files.

Secure File Uploads

A set of security measures to prevent malicious files from being uploaded and executed on a web server.

  • Always perform server-side validation.
  • Validate file type (magic bytes), extension, and size.
  • Store uploaded files in non-executable directories.
  • Rename files to prevent path traversal and ensure unique names.

Memory trick: Uploads need a 'Magic Whitelist' on the server.

More Web Application Hacking questions