EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
An ethical hacker is performing a penetration test on a web application that processes user-uploaded images. They discover that the application checks the file extension on the client-side (e.g., `.jpg`, `.png`) but does not perform any server-side validation of the file's actual content type. The hacker successfully uploads a web shell disguised as an image. Which vulnerability did the ethical hacker exploit?
- ACross-Site Request Forgery (CSRF)
- BInsecure Direct Object Reference (IDOR)
- CUnrestricted File Upload
- DServer-Side Request Forgery (SSRF)
Show answer & explanationAnswer & explanation
Correct answer: C. Unrestricted File Upload
The ability to upload arbitrary files, including malicious ones like web shells, due to insufficient server-side validation of file content or type, is known as Unrestricted File Upload. Client-side checks are easily bypassed.
Why the other options are wrong
- A. CSRF tricks authenticated users into performing unintended actions, unrelated to file uploads.
- B. IDOR involves accessing resources directly by manipulating their identifiers, not file uploads.
- D. SSRF makes the server perform requests to an arbitrary domain, not about uploading malicious files to the server itself.
Unrestricted File Upload
A vulnerability that occurs when a web application allows users to upload files without properly validating their type or content, enabling attackers to upload malicious files (e.g., web shells) that can then be executed on the server.
- Lack of server-side file validation.
- Allows upload of malicious files (e.g., web shells).
- Can lead to remote code execution (RCE).
Memory trick: If the file check is flimsy, the shell will be frisky.