inspecting files to search for imagetragick-exploit-codes

9 views
Skip to first unread message

mex

unread,
May 9, 2016, 4:51:17 PM5/9/16
to naxsi-discuss
is it possible with naxsi to inspect files in POST-payload
to find exploit-codes?

https://imagetragick.com/

cloudflare sez they can has mod_sec rules to discover
such behavior (dunno if mod_sec is able to inspect
files)

mabe we just stop uploading mvg/svg - files
with a generic rule?



thoughts?
Reply all
Reply to author
Forward
0 new messages