
Understanding File Upload Security for Web Applications
- Abstract
PDF Full Text
In today’s times the web model has become an important mechanism in terms of information and services delivery over the internet. With the success of the internet, it becomes important to take into account the security of the web application layer from various unauthorized user attacks. The main reason for security awareness is due to lack of trustworthiness of the applications programming logic or input validation. The best way of preventing application exploitability is to enforce good security policies through the applications. This can be done only when the client and server collaborate to achieve the desired security goals eliminating the possibility of such attacks. In this paper we focus on file upload exploits with respect to web application security. Various test cases will be explained along with the impact which will help security testers and application developers to maintain the confidentiality and integrity of user data. Finally, potential steps for mitigation will be provided in order to restrict such attacks.