TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Show HN: File Upload Hacking Challenges

36 点作者 emeth大约 9 年前

2 条评论

orf大约 9 年前
PHP's file-based layout is one of the biggest mistakes in web security I can imagine, coupled with the lack of a built in secure file upload functions. I've seen so many websites coded with checks like "if .jpeg in filename", which is easily bypassed. Then once the file is up there you just have to navigate to it and BAM, you have RCE and a shell. Ridiculous.
gravypod大约 9 年前
I remember messing around with hack this site a long time ago. This looks like it will be a valuable lesson for all of the php devs out there who don't handle files often.