如何防范纯文本表单被篡改发起的文件上传攻击?
Nice catch—this is a common client-side tampering attack that can drain server resources (bandwidth, storage, processing power) if left unaddressed. Since attackers can modify form HTML and request headers freely, all critical validation has to happen server-side. Here are actionable steps to block this abuse:
Validate the request's content type
Your original text-only form uses the defaultapplication/x-www-form-urlencodedcontent type. On the server (e.g., in PHP, check$_SERVER['CONTENT_TYPE']), reject any request that usesmultipart/form-datafor this specific form endpoint. Never trust the client's declared enctype—enforce the expected encoding server-side.Strictly enforce field types and ignore unexpected file data
For fields that should be text (likelnamein your example), verify they exist in the standard POST parameters (e.g.,$_POST['lname']in PHP) instead of the file upload array ($_FILES). If you find any entries in$_FILESfor fields that shouldn't accept files, immediately reject the request. You should also validate the content of text fields (e.g., length, allowed characters) to ensure they match expected input.Enforce strict request size limits
Set server-level limits on request payload size to prevent large files from being uploaded even if other checks fail. In PHP, adjustupload_max_filesizeandpost_max_sizeinphp.ini. For web servers like Nginx or Apache, configure request body size limits (e.g.,client_max_body_sizein Nginx) to block oversized requests before they reach your application code.Avoid relying on client-side form structure
Your server should have a clear definition of what fields are allowed for each form. Only process the expected text fields (fnameandlnamein this case) and discard any unexpected parameters or file data. Don't dynamically handle fields based on what the client sends—stick to your predefined form schema.Add anti-tampering tokens (optional but powerful)
Include a hidden signed token in your form (e.g.,form_tokengenerated with HMAC using a server-side secret). When processing the request, verify the token's signature. If the token is missing, modified, or invalid, reject the request. This makes it harder for attackers to alter the form structure and submit a valid request.
内容的提问来源于stack exchange,提问作者Vikas Kandari

