Vor Kurzem aufgerufene Suchen
Keine vor kurzem aufgerufene Suchen

Login Test
Beigetreten 15. Apr. 2021
·
Letzte Aktivität 22. Okt. 2021
Folge ich
0
Follower
0
Gesamtaktivitäten
2
Stimmen
0
Abonnement
1
AKTIVITÄTSÜBERSICHT
BADGES
BEITRÄGE
POSTS
COMMUNITY-KOMMENTARE
BEITRAGSKOMMENTARE
AKTIVITÄTSÜBERSICHT
Neueste Aktivität von Login Test
Login Test hat einen Post erstellt
zendesk, allows any arbitrary file to uploaded. This highly makes application vulnerable to several type of attacks. I found that by domain/application is vulnerable because it allows all type file to be uploaded while creating a ticket. As you can see in attached image, I've uploaded firefox installer.exe.
As an impact, attacker can exploit this vulnerability in many ways to perform malicious activity. Attacker can create a ticket and upload malware(virus, worm, ransomware etc.). Later, when the ticket is handled by support person, he/she will check the ticket and open the file. This file can be installed in the system and perform many malicious activities. It can compromise the system, and/or entire network depend on the malware.
Ideally as a solution, only limited set/type of files should be allowed for upload such as jpg, png, .txt etc. Kindly let me know your feedback on this, and if this falls in your scope.
Security is not a choice any more and this should be implemented/fixed ASAP.
Gepostet 09. Apr. 2020 · Login Test
3
Follower
11
Stimmen
10
Kommentare