File-upload-attacks
Last updated
Last updated
gi### Web Shells
: Basic web shell for PHP
: Reverse shell for PHP
: List of common web and reverse shells
Blacklist Bypass
shell.phtml
### Uncommon Extension
shell.pHp
### Case Manipulation
Whitelist Bypass
shell.jpg.php
### Double Extension
shell.php.jpg
### Reverse Double Extension
%20, %0a, %00, %0d0a, /, .\, ., …
### Character Injection - Before/After Extension
XSS
HTML, JS, SVG, GIF
XXE/SSRF
XML, SVG, PDF, PPT, DOC
DoS
ZIP, JPG, PNG
: List of PHP extensions
: List of ASP extensions
: List of web extensions
: List of web content-types
: List of all content-types
: List of file signatures/magic bytes