:. Home
:. About Me
:. Beer
:. Music
:. Pictures
:. Projects
  => Windows Programs
  => Server Scripts
  => Electronics
  => Writings
  => Handyman
  => Other
:. Links
Spring 2008
Lots of people use the mime-type property of an upload to determine if it should be allowed. This is especially common with people who allow image uploads. This is a proof of concept exploiter.
Download
1: mimeTypeUploadExploit.zip
[6.44kB]

:. Project / Mime Upload Exploiter

Far too many people rely on the mime-type of an upload to determine if it's "ok." Unbeknownst to them, the mime-type can be forged. This program is meant as a proof to that. Please only test on your own host. I won't be responsible for what you use it for.