Radasync Arbitrary File Upload Alternatives

AsyncUploadHandler in Telerik's RadAsyncUpload feature is configured with a hard coded (default) encryption key. This key is used to encrypt upload variables which are sent to the user, and subsequently used in file upload requests by the user to the server. If this key is not changed from it's default value of \"PrivateKeyForEncryptionOfRadAsyncUploadConfiguration\", a malicious actor can capture the file upload request to /Telerik.Web.Ui.WebResource.axd and decrypt parameter 'rauPostData'. Once decrypted, the file upload location can be modified and re-encrypted, resulting in arbitrary file upload to any location on the server which the web server user has permissions to write to.
Suggest Alternative
Alternatives To ac3lives/RadAsync-Arbitrary-File-Upload
Project Name Stars Downloads Repos Using This Packages Using This Most Recent Commit Total Releases Latest Release Open Issues License Language
diafygi/gethttpsforfree 2,130 0 0 over 3 years ago 0 16 mit JavaScript
Source code for https://gethttpsforfree.com/
passwall/passwall-server 702 0 0 almost 3 years ago 21 August 22, 2022 9 agpl-3.0 Go
Passwall Server is the core backend infrastructure for Passwall platform
gellin/bantam 186 0 0 almost 5 years ago 0 0 mit C#
A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.
KishanBagaria/padding-oracle-attacker 150 2 3 about 4 years ago 14 March 30, 2020 0 mit TypeScript
🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.
claustromaniac/httpz 47 0 0 over 6 years ago 0 18 gpl-3.0 JavaScript
Fat-free hardenable opportunistic encryption for Firefox
devlab-oy/sepa 30 0 0 over 3 years ago 22 September 26, 2017 8 mit Ruby
An open source Ruby implementation of SEPA Financial Messages using Web Services.
tzsk/crypton 27 0 0 over 4 years ago 5 November 11, 2020 6 mit PHP
Laravel Request & Response Encryption
aeris/acme-pki 16 1 0 almost 6 years ago 9 June 20, 2020 1 agpl-3.0 Ruby
Tiny ACME PKI
andyzib/LetsEncrypt-PRTG 15 0 0 over 3 years ago 0 0 mit PowerShell
Post request script to install an SSL certificate obtained with Certify the Web or win-acme in PRTG.
open-template-hub/payment-server-template 15 0 0 about 2 years ago 0 0 mit TypeScript
Payment Server Template is a generic open-source payment server that has a simple yet powerful design to connect your business with third-party payment solution provider companies (like Stripe or Coinbase).
Alternatives To ac3lives/RadAsync-Arbitrary-File-Upload
Select To Compare


Alternative Project Comparisons
Popular Request Projects
Popular Encryption Projects
Popular Networking Categories
Related Searches
Get A Weekly Email With Trending Projects
No Spam. Unsubscribe easily at any time.
Privacy | About | Terms | Follow Us On Twitter

Downloads, Dependent Repos, Dependent Packages, Total Releases, Latest Releases data powered by Libraries.io.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.