Strix•不安全文件上传 - File Upload Security Testing
Security testing manual for file upload vulnerabilities including extension bypass, Content-Type manipulation, and path traversal
Tags
Updated: 2026-05-11Capabilities
Typical Inputs
Typical Outputs
What this skill does
- identify upload endpoints
- probe file type validation
- test extension bypass
- construct polyglot files
- create archive payloads
- manipulate Content-Type
- inject path traversal
- bypass filename filters
- probe resumable uploads
- exploit cloud presigned URLs
- trigger file processors
- test Content-Disposition
- extract archive files
- analyze response headers
- upload test files
Inputs
- upload endpoint
- file payload
- upload form field
- multipart boundary
- presigned URL
- cloud storage bucket
- archive file
- image file
- document file
Outputs
- vulnerability report
- file upload URL
- execution confirmation
- bypass evidence
- response headers
- exploit payload
- validation result
Requirements
- web application with file upload
- API upload endpoint
- object storage access
- file processing pipeline
- internet connection
