Scribe
Scribe

Gostou? Torne o Scribe ainda melhor deixando uma avaliação

Obter Extensão do Chrome

Navegar

  • Vídeos Populares
  • Vídeos Recentes
  • Todos os Canais

Ferramentas Gratuitas

  • Baixador de Legendas de Vídeo
  • Gerador de Marcadores de Tempo de Vídeo
  • Resumidor de Vídeos
  • Contador de Palavras de Vídeo
  • Analisador de Títulos de Vídeo
  • Busca de Transcrições de Vídeo
  • Análises de Vídeo
  • Criador de Capítulos de Vídeo
  • Gerador de Quiz de Vídeo
  • Chat com Vídeo

Produto

  • Preços
  • Blog
  • Obter Extensão do Chrome

Developers

  • Transcript API
  • API Documentation

Legal

  • Termos
  • Privacidade
  • Suporte
  • Mapa do Site

Direitos Autorais © 2026. Feito com ♥ por Scribe

— Se isso tornou sua vida mais fácil (ou pelo menos um pouco menos caótica), deixe-nos uma avaliação! Prometemos que vai alegrar nosso dia. 😊

Related Videos

★ ★ ★ Upload Size (Improper Input Validation)

Video thumbnail
7.63k624 Palavras3m readGrade 18
Compartilhar
Channel
Hacksplained
hey what's up guys hacksplain here today we're going to have a look at the upload size challenge now the description says we should upload a file which is larger than 100 kilobytes and this falls under the improper input validation challenges so let's scroll up a little bit and see where we do have an upload functionality and i actually already scouted the website a little bit and i found that under the complaint section over here we can upload an invoice and there's a browse button right over here so let's try to upload a file i'm having
a file over here which is called doc one pdf i'll put down a message saying astf it doesn't really matter i will submit this and yep we are getting a message saying customer support will get in touch with you soon your complaint reference is number two and if we have a look at that we see that there was a post request going out to slash file minus upload and you can see the pdf upload right down below here so all that red stuff is the pdf that i was sending to the web server and you
can see over here that i was sending an application pdf content type so what happens if i send a file which is a little bigger so now i'm trying to send a file which is bigger than 100 kilobytes as you can see over here and the client-side controls right now actually only allow me to upload a file which has a maximum of 100 kilobytes so what can we do in order to circumvent the client-side controls that's pretty easy we go back to burb we're still having this request open that is needed to upload a file
we click on control r to send this request to a repeater we check out repeater we can set this again just to check if it still works it does and it responds with a 24 no content response so instead of sending this file right now which is smaller than 100 kilobytes let's try to send one which is bigger so i'm going to open up notepad right now and open the the bigger pdf file in notepad and copy it straight into burp's repeater all right so you can see that i'm having doc to pdf open notepad
and it basically looks like a lot of garbage because notepad cannot render a pdf file but what we can do is we can just copy all the information all the data and move over here to burps repeater and now we gotta substitute all that information which we find over here so i'm scrolling down to the very bottom of the request and if we're finished which will happen in just a bit right now we will delete that and fill in our new content so now i'm uploading a file which is bigger than 100 kilobytes now we'll
just go ahead and click on send and what we see over here is that we're receiving a 204 no content response once again which kind of means that the file was uploaded and if we check back to os2 shop we can see that we've successfully solved the challenge which is upload size upload the file larger than 100 kilobytes so that was it for today so you should have learned that you should never trust client-side controls as a company or if you are on the attacker side make sure to circumvent client-side controls by using a tool
like burp suite alright thank you for watching subscribe in the top right corner and yeah check out all my other videos [Music] you
Vídeos relacionados
★ ★ ★ Upload Type (Improper Input Validation)
3:45
★ ★ ★ Upload Type (Improper Input Validation)
Hacksplained
5,801 views
FREE Malware Removal Tools That Actually Work!
27:21
FREE Malware Removal Tools That Actually W...
Ask Your Computer Guy
3,589 views
Bug Bounty Live Recon - Grabbing Domains!
10:28
Bug Bounty Live Recon - Grabbing Domains!
Hacksplained
5,411 views
Bug Bounty Live Recon - Linked / JS Discovery!
8:26
Bug Bounty Live Recon - Linked / JS Discov...
Hacksplained
3,983 views
GDPR Data Erasure - Broken Authentication | OWASP Juice Shop Solution
5:33
GDPR Data Erasure - Broken Authentication ...
Cyberw1ng
41 views
SQL Fundamentals | Cybersecurity 101 Learning Path - TryHackMe
51:37
SQL Fundamentals | Cybersecurity 101 Learn...
Angel Aguirre
148 views
5 Middle Class Habits Keeping You Poor
13:12
5 Middle Class Habits Keeping You Poor
Liam Porritt
21,139 views
TryHackMe's Day 6 of Advent of Cyber 2024
19:48
TryHackMe's Day 6 of Advent of Cyber 2024
MBxCyberSec
70 views
Hashing Basics | Cybersecurity 101 Learning Path - TryHackMe
1:06:47
Hashing Basics | Cybersecurity 101 Learnin...
Angel Aguirre
120 views
TryHackMe's Day 4 of Advent of Cyber 2024
26:27
TryHackMe's Day 4 of Advent of Cyber 2024
MBxCyberSec
82 views
Networking Core Protocols | Cybersecurity 101 Learning Path | TryHackMe
31:29
Networking Core Protocols | Cybersecurity ...
Angel Aguirre
144 views
HTTP Parameter Pollution! December Tip of the Day #17
0:57
HTTP Parameter Pollution! December Tip of ...
Hacksplained
480 views
Gobuster: The Basics | Cybersecurity 101 Learning Path - TryHackMe
54:07
Gobuster: The Basics | Cybersecurity 101 L...
Angel Aguirre
198 views
Pentesting FAQ: Our Penetration Tester Answers the Internet's Most Asked Questions
41:54
Pentesting FAQ: Our Penetration Tester Ans...
VerSprite
1,989 views
Python Data Analysis Project: Sales Consultant Insights
27:53
Python Data Analysis Project: Sales Consul...
DataWithDilan
304 views
SE4458 - 23070006102 - AirBnb like ASP.net Core Backend Project
8:10
SE4458 - 23070006102 - AirBnb like ASP.net...
Egemen Ozyurek
25 views
AWS re:Invent 2024 - Building an AI-powered shopping assistant  (RCG204)
13:22
AWS re:Invent 2024 - Building an AI-powere...
AWS Events
489 views
TryHackMe Advent of Cyber 2024 - Day 1
20:20
TryHackMe Advent of Cyber 2024 - Day 1
wizarddos
180 views
Ac 230 volt convert to 12 volt dc|12 volt power supply making|led driver circuit
2:19
Ac 230 volt convert to 12 volt dc|12 volt ...
Do shorts
38 views
Networking Secure Protocols || Cybersecurity 101 Learning Path || TryHackMe
46:35
Networking Secure Protocols || Cybersecuri...
Angel Aguirre
45 views