new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

file upload security

4 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

File Upload Cheat Sheet available

The File Upload Cheat Sheet is available in the OWASP series covering secure file upload handling.

Input validation DoS defense: limit file upload size and extensions

Limit file upload size and allowed extensions to prevent DoS on file storage and functions that use uploads as input (such as image resizing or PDF creation). This prevents resource exhaustion attacks.

V12.1 File Upload Requirements references File Upload Cheat Sheet

For secure file upload handling covered under V12.1 File Upload Requirements, OWASP references the Protect File Upload Against Malicious File cheat sheet.

File upload security cheat sheet reference

The OWASP ASVS index references the File Upload Cheat Sheet under V1.2 Injection Prevention and V5 File Handling sections (V5.1, V5.2, V5.4), indicating it is the primary resource for secure file upload handling guidance.

Give your agent this brain