Even though the names of uploaded files are random, fuzzer utilities can be used to discover content on the server.
Related questions are:
- How can
rustypaste be affected by such situation?
- Need a demonstration of fuzzing with rustbuster or a similar tool.
- Should there be any precautions for preventing this?
- Implement blocking user-agents for common fuzzer tools (?)
- Should we do anything?
I think it is an interesting topic and needs some brainstorming for improving security.
Even though the names of uploaded files are random, fuzzer utilities can be used to discover content on the server.
Related questions are:
rustypastebe affected by such situation?I think it is an interesting topic and needs some brainstorming for improving security.