Radasync Arbitrary File Upload

AsyncUploadHandler in Telerik's RadAsyncUpload feature is configured with a hard coded (default) encryption key. This key is used to encrypt upload variables which are sent to the user, and subsequently used in file upload requests by the user to the server. If this key is not changed from it's default value of "PrivateKeyForEncryptionOfRadAsyncUploadConfigurat a malicious actor can capture the file upload request to /Telerik.Web.Ui.WebResource.axd and decrypt parameter 'rauPostData'. Once decrypted, the file upload location can be modified and re-encrypted, resulting in arbitrary file upload to any location on the server which the web server user has permissions to write to.
Alternatives To Radasync Arbitrary File Upload
Project NameStarsDownloadsRepos Using ThisPackages Using ThisMost Recent CommitTotal ReleasesLatest ReleaseOpen IssuesLicenseLanguage
Gethttpsforfree2,130
2 years ago16mitJavaScript
Source code for https://gethttpsforfree.com/
Bantam186
3 years agomitC#
A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.
Padding Oracle Attacker15022 years ago14March 30, 2020mitTypeScript
🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.
Httpz47
5 years ago18gpl-3.0JavaScript
Fat-free hardenable opportunistic encryption for Firefox
Sepa30
2 years ago22September 26, 20178mitRuby
An open source Ruby implementation of SEPA Financial Messages using Web Services.
Crypton27
3 years ago5November 11, 20206mitPHP
Laravel Request & Response Encryption
Acme Pki16
14 years ago9June 20, 20201agpl-3.0Ruby
Tiny ACME PKI
Payment Server Template15
5 months agomitTypeScript
Payment Server Template is a generic open-source payment server that has a simple yet powerful design to connect your business with third-party payment solution provider companies (like Stripe or Coinbase).
Letsencrypt Prtg15
2 years agomitPowerShell
Post request script to install an SSL certificate obtained with Certify the Web or win-acme in PRTG.
Laravel Encrypted Api14
6 years ago1October 09, 2017mitPHP
Encrypted API communication between Laravel applications
Alternatives To Radasync Arbitrary File Upload
Select To Compare


Alternative Project Comparisons
Popular Request Projects
Popular Encryption Projects
Popular Networking Categories

Get A Weekly Email With Trending Projects For These Categories
No Spam. Unsubscribe easily at any time.
C Sharp
Upload
Location
Actor
File Upload