[Day 15] Secure Coding
December 15, 2022
Last updated
December 15, 2022
Last updated
Today was a different day for AOC as I learned about secure programming with file uploads. This is something interesting to me as it helps me understand different approaches the developers may make when creating file uploads and how they may be exploited. I would highly recommend checking out this room to understand what developers could use in a file upload.
unrestricted
santasidekick2
THM{Naughty.File.Uploads.Can.Get.You.RCE}
Also, a side note in your meterpreter session you can use 'getsystem' for NT_Auth
File Extension Validation
File Renaming
Malware Scanning