Web Hack List

Collected research

Reflected File Download

Reflected File Download - A New Web Attack Vector

Reflected File Download turns a trusted site into a malware host without any upload: a URL whose input is reflected into the response, typically a JSON or JSONP API, is given extra permissive path segments so the browser saves the reply as an executable .bat or .cmd file. The victim sees a download from a trusted domain over HTTPS, and running it executes attacker-supplied shell commands.

Record

Document
Reflected File Download - A New Web Attack Vector
Researcher
Oren Hafif
Published by
Trustwave Holdings, Inc.
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Oren Hafif, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .