5 ms·
Don't joke. I have had security people report my stuff is insecure because there is a document upload feature and a user could upload a virus and name it virus.
by baroffoos 7y ago
Don't joke. I have had security people report my stuff is insecure because there is a document upload feature and a user could upload a virus and name it virus.png and then a user could download it and rename it to virus.exe and run it.
- fulafel 7y agoChange the scenario to "download it and double click it, exploiting vuln in file format handler" and it's correct.
- baroffoos 7y agoAt that point you may as well ban all user generated content since one user might have an insecure OS
- fulafel 7y agoWell, security engineering is about tradeoffs and managing risk, you won't get far outlawing all sources of risk. The smart way to handle attachments is to scrub them somehow (re-encode, pdf2pdf etc).
- badrabbit 7y agoThat is actually a serious issue especially if you allow unicode and RTL override in the file name. Always validate input file type.