How to analyze the loophole of file upload in big data
Today, I would like to talk to you about the analysis of file upload loopholes in big data. Many people may not know much about it. In order to make you understand better, the editor has summarized the following contents for you. I hope you can gain something according to this article.
Environment: dvwa
2. Select Upload,low level
1. Uploading 1.php files and 1.jpg files is no problem.
The content of the PHP file is:
2. Visit the files we uploaded
Http://192.168.152.188/dvwa/hackable/uploads/1.jpg
You can see the picture
Http://192.168.152.188/dvwa/hackable/uploads/1.php
I can't see anything.
3. Link the 1.php file with a kitchen knife and click add
4. Double-click the link to enter
Third, select the Upload,medium level
1. Upload 2.php file and 2.jpg file, and find that 2.php cannot be uploaded
2. Click view source
3. The upload type is limited here, and the upload type is modified by grabbing the package.
4. We modified text/plain to image/jpeg and uploaded it successfully.
5. Link it with a kitchen knife
4. Select the Upload,high level
After reading the above, do you have any further understanding of big data's analysis of file upload vulnerabilities? If you want to know more knowledge or related content, please follow the industry information channel, thank you for your support.