You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何防范纯文本表单被篡改发起的文件上传攻击?

How to Prevent Unauthorized File Uploads from Tampered Text-Only Forms

Nice catch—this is a common client-side tampering attack that can drain server resources (bandwidth, storage, processing power) if left unaddressed. Since attackers can modify form HTML and request headers freely, all critical validation has to happen server-side. Here are actionable steps to block this abuse:

  • Validate the request's content type
    Your original text-only form uses the default application/x-www-form-urlencoded content type. On the server (e.g., in PHP, check $_SERVER['CONTENT_TYPE']), reject any request that uses multipart/form-data for this specific form endpoint. Never trust the client's declared enctype—enforce the expected encoding server-side.

  • Strictly enforce field types and ignore unexpected file data
    For fields that should be text (like lname in your example), verify they exist in the standard POST parameters (e.g., $_POST['lname'] in PHP) instead of the file upload array ($_FILES). If you find any entries in $_FILES for fields that shouldn't accept files, immediately reject the request. You should also validate the content of text fields (e.g., length, allowed characters) to ensure they match expected input.

  • Enforce strict request size limits
    Set server-level limits on request payload size to prevent large files from being uploaded even if other checks fail. In PHP, adjust upload_max_filesize and post_max_size in php.ini. For web servers like Nginx or Apache, configure request body size limits (e.g., client_max_body_size in Nginx) to block oversized requests before they reach your application code.

  • Avoid relying on client-side form structure
    Your server should have a clear definition of what fields are allowed for each form. Only process the expected text fields (fname and lname in this case) and discard any unexpected parameters or file data. Don't dynamically handle fields based on what the client sends—stick to your predefined form schema.

  • Add anti-tampering tokens (optional but powerful)
    Include a hidden signed token in your form (e.g., form_token generated with HMAC using a server-side secret). When processing the request, verify the token's signature. If the token is missing, modified, or invalid, reject the request. This makes it harder for attackers to alter the form structure and submit a valid request.

内容的提问来源于stack exchange,提问作者Vikas Kandari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:00:39