vulns.co
/
GKData.io MCP

Back to Bypasses

Upload validation boundaries

Assess whether uploads are constrained by extension, content signature, storage location, retrieval headers, and authorization. Use tiny inert fixtures and an account you control; never upload executable or active content.

Tags: upload, validation, storage, authorized-testing

Techniques

Type validation

Compare declared content type, filename extension, and actual benign file bytes to identify which signal the service trusts.

  • hello.txt containing plain UTF-8 text
  • image.png containing a known-valid 1x1 PNG

Serving boundary

After a permitted upload, inspect download headers, origin, and cache controls. The safe outcome is attachment delivery or a non-executable media context.

  • Verify Content-Disposition, Content-Type, and X-Content-Type-Options
  • Use a unique benign filename for retrieval tracing

Access control

Confirm another controlled account cannot list, fetch, replace, or delete the test upload without permission.

  • two-account access check on an owned upload ID
  • delete attempt only where the program permits controlled state changes