{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:14:47Z","timestamp":1750220087118,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,8,23]],"date-time":"2022-08-23T00:00:00Z","timestamp":1661212800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,8,23]]},"DOI":"10.1145\/3538969.3538999","type":"proceedings-article","created":{"date-parts":[[2022,8,17]],"date-time":"2022-08-17T23:41:40Z","timestamp":1660779700000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["FileUploadChecker: Detecting and Sanitizing Malicious File Uploads in Web Applications at the Request Level"],"prefix":"10.1145","author":[{"given":"Pascal","family":"Wichmann","sequence":"first","affiliation":[{"name":"Security in Distributed Systems, Universit\u00e4t Hamburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Groddeck","sequence":"additional","affiliation":[{"name":"Universit\u00e4t Hamburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hannes","family":"Federrath","sequence":"additional","affiliation":[{"name":"Security in Distributed Systems, Universit\u00e4t Hamburg, Security in Distributed Systems, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,8,23]]},"reference":[{"volume-title":"ACM Southeast Regional Conference.","author":"S.","key":"e_1_3_2_1_1_1","unstructured":"Nasser\u00a0S. Alamri and William\u00a0H. Allen. 2014. A taxonomy of file-type identification techniques. In ACM Southeast Regional Conference."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2963724"},{"key":"e_1_3_2_1_3_1","unstructured":"Thomas Boutell and Tom Lane. 1996. PNG Specification: File Signature. http:\/\/www.libpng.org\/pub\/png\/spec\/1.0\/PNG-Rationale.html#R.PNG-file-signature (accessed October 15 2021)."},{"key":"e_1_3_2_1_4_1","unstructured":"Web Application\u00a0Security Consortium. 2006. Web Application Firewall Evaluation Criteria. https:\/\/projects.webappsec.org\/f\/wasc-wafec-v1.0.pdf"},{"key":"e_1_3_2_1_5_1","article-title":"A comparison of static, dynamic, and hybrid analysis for malware detection","volume":"13","author":"Damodaran Anusha","year":"2017","unstructured":"Anusha Damodaran, Fabio\u00a0Di Troia, Corrado\u00a0Aaron Visaggio, Thomas\u00a0H. Austin, and Mark Stamp. 2017. A comparison of static, dynamic, and hybrid analysis for malware detection. J. Comput. Virol. Hacking Tech. 13, 1 (2017).","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180337.1180344"},{"key":"e_1_3_2_1_7_1","volume-title":"FFMPEG Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-3611\/product_id-6315\/Ffmpeg-Ffmpeg.html (accessed","author":"Details CVE","year":"2021","unstructured":"CVE Details. 2021. FFMPEG Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-3611\/product_id-6315\/Ffmpeg-Ffmpeg.html (accessed October 15, 2021)."},{"key":"e_1_3_2_1_8_1","volume-title":"Imagemagick Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-1749\/Imagemagick.html (accessed","author":"Details CVE","year":"2021","unstructured":"CVE Details. 2021. Imagemagick Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-1749\/Imagemagick.html (accessed October 15, 2021)."},{"key":"e_1_3_2_1_9_1","volume-title":"Python Pillow Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-10210\/product_id-27460\/Python-Pillow.html (accessed","author":"Details CVE","year":"2021","unstructured":"CVE Details. 2021. Python Pillow Security Vulnerabilities. https:\/\/www.cvedetails.com\/vulnerability-list\/vendor_id-10210\/product_id-27460\/Python-Pillow.html (accessed October 15, 2021)."},{"key":"e_1_3_2_1_10_1","volume-title":"Flask Documentation: Becoming Big. Wrap with middleware. https:\/\/flask.palletsprojects.com\/en\/2.0.x\/becomingbig\/ (accessed","author":"Developers Flask","year":"2021","unstructured":"Flask Developers. 2021. Flask Documentation: Becoming Big. Wrap with middleware. https:\/\/flask.palletsprojects.com\/en\/2.0.x\/becomingbig\/ (accessed October 15, 2021)."},{"key":"e_1_3_2_1_11_1","volume-title":"7th International Conference, DIMVA.","author":"Doup\u00e9 Adam","year":"2010","unstructured":"Adam Doup\u00e9, Marco Cova, and Giovanni Vigna. 2010. Why Johnny Can\u2019t Pentest: An Analysis of Black-Box Web Vulnerability Scanners. In Detection of Intrusions and Malware, and Vulnerability Assessment, 7th International Conference, DIMVA."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"R. Fielding and J. Reschke. 2014. Hypertext Transfer Protocol (HTTP\/1.1): Message Syntax and Routing. RFC 7230.","DOI":"10.17487\/rfc7230"},{"key":"e_1_3_2_1_14_1","volume-title":"Django Documentation: Middleware. https:\/\/docs.djangoproject.com\/en\/3.2\/topics\/http\/middleware\/ (accessed","author":"Foundation Django\u00a0Software","year":"2021","unstructured":"Django\u00a0Software Foundation. 2021. Django Documentation: Middleware. https:\/\/docs.djangoproject.com\/en\/3.2\/topics\/http\/middleware\/ (accessed October 15, 2021)."},{"key":"e_1_3_2_1_15_1","volume-title":"Technical Report","author":"Foundation OWASP","year":"2021","unstructured":"OWASP Foundation. 2021. OWASP Top 10 - 2021. Technical Report. OWASP Foundation. https:\/\/owasp.org\/Top10\/ (accessed October 21, 2021)."},{"key":"e_1_3_2_1_16_1","volume-title":"Risks and Security of Internet and Systems - 15th International Conference, CRiSIS","author":"Fredj Ouissem\u00a0Ben","year":"2020","unstructured":"Ouissem\u00a0Ben Fredj, Omar Cheikhrouhou, Moez Krichen, Habib Hamam, and Abdelouahid Derhab. 2020. An OWASP Top Ten Driven Survey on Web Application Protection Methods. In Risks and Security of Internet and Systems - 15th International Conference, CRiSIS 2020. Springer, 235\u2013252."},{"key":"e_1_3_2_1_17_1","unstructured":"Gustavo Henke and express-validator contributors. 2021. express-validator. https:\/\/express-validator.github.io\/"},{"key":"e_1_3_2_1_18_1","volume-title":"UChecker: Automatically Detecting PHP-Based Unrestricted File Upload Vulnerabilities. In 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks.","author":"Huang Jin","year":"2019","unstructured":"Jin Huang, Yu Li, Junjie Zhang, and Rui Dai. 2019. UChecker: Automatically Detecting PHP-Based Unrestricted File Upload Vulnerabilities. In 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks."},{"key":"e_1_3_2_1_19_1","volume-title":"Django Upload Validator. https:\/\/github.com\/mckinseyacademy\/django-upload-validator (accessed","author":"Ilyas Naeem","year":"2021","unstructured":"Naeem Ilyas, Giovanni\u00a0Cimolin da Silva, and Kshitij Sobti. 2019. Django Upload Validator. https:\/\/github.com\/mckinseyacademy\/django-upload-validator (accessed June 17, 2021)."},{"key":"e_1_3_2_1_20_1","volume-title":"fuxploider. https:\/\/github.com\/almandin\/fuxploider. (accessed","author":"Jarry Virgile","year":"2022","unstructured":"Virgile Jarry and GitHub Contributors. 2021. fuxploider. https:\/\/github.com\/almandin\/fuxploider. (accessed June 14, 2022)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23126"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329841"},{"key":"e_1_3_2_1_23_1","volume-title":"Laravel Image Sanitize. https:\/\/github.com\/laravel-at\/laravel-image-sanitize (accessed","author":"N\u00fcrnberger Adrian","year":"2021","unstructured":"Adrian N\u00fcrnberger and Mathias Onea. 2021. Laravel Image Sanitize. https:\/\/github.com\/laravel-at\/laravel-image-sanitize (accessed May 3, 2021)."},{"key":"e_1_3_2_1_24_1","volume-title":"International Journal of Engineering Trends and Technology","author":"Pooj Karishma","year":"2016","unstructured":"Karishma Pooj and Sonali Patil. 2016. Understanding File Upload Security for Web Applications. International Journal of Engineering Trends and Technology (2016)."},{"volume-title":"Information Systems Security - 11th International Conference, ICISS.","author":"Prandl Stefan","key":"e_1_3_2_1_25_1","unstructured":"Stefan Prandl, Mihai\u00a0M. Lazarescu, and Duc-Son Pham. 2015. A Study of Web Application Firewall Solutions. In Information Systems Security - 11th International Conference, ICISS."},{"key":"e_1_3_2_1_26_1","volume-title":"express-autosanitizer. https:\/\/github.com\/antoniormrzz\/express-autosanitizer (accessed","author":"Ramirez Antonio","year":"2021","unstructured":"Antonio Ramirez. 2021. express-autosanitizer. https:\/\/github.com\/antoniormrzz\/express-autosanitizer (accessed June 17, 2021)."},{"key":"e_1_3_2_1_27_1","volume-title":"Symfony Documentation: How to Set Up Before and After Filters. https:\/\/symfony.com\/doc\/current\/event_dispatcher\/before_after_filters.html (accessed","author":"Symfony","year":"2021","unstructured":"Symfony SAS. 2021. Symfony Documentation: How to Set Up Before and After Filters. https:\/\/symfony.com\/doc\/current\/event_dispatcher\/before_after_filters.html (accessed October 15, 2021)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.18517\/ijaseit.8.4-2.6827"},{"key":"e_1_3_2_1_29_1","volume-title":"ClamAV open-source anti-virus engine. https:\/\/www.clamav.net (accessed","author":"Team AV","year":"2021","unstructured":"The\u00a0ClamAV Team. 2021. ClamAV open-source anti-virus engine. https:\/\/www.clamav.net (accessed October 4, 2021)."},{"key":"e_1_3_2_1_30_1","unstructured":"Pascal Wichmann Alexander Groddeck and Hannes Federrath. 2022. PyPi: Django Middleware Proof of Concept Implementation of FileUploadChecker. https:\/\/pypi.org\/project\/django-middleware-fileuploadvalidation\/"},{"key":"e_1_3_2_1_31_1","volume-title":"InteGuard: Toward Automatic Protection of Third-Party Web Service Integrations. In 20th Annual Network and Distributed System Security Symposium, NDSS 2013","author":"Xing Luyi","year":"2013","unstructured":"Luyi Xing, Yangyi Chen, XiaoFeng Wang, and Shuo Chen. 2013. InteGuard: Toward Automatic Protection of Third-Party Web Service Integrations. In 20th Annual Network and Distributed System Security Symposium, NDSS 2013, San Diego, California, USA, February 24-27, 2013. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss2013\/integuard-toward-automatic-protection-third-party-web-service-integrations"},{"key":"e_1_3_2_1_32_1","unstructured":"Jason Zhang. 2018. MLPdf: an effective machine learning based approach for PDF malware detection. arXiv preprint arXiv:1808.06991(2018)."}],"event":{"name":"ARES 2022: The 17th International Conference on Availability, Reliability and Security","acronym":"ARES 2022","location":"Vienna Austria"},"container-title":["Proceedings of the 17th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3538999","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3538969.3538999","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:40Z","timestamp":1750183780000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3538969.3538999"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,23]]},"references-count":31,"alternative-id":["10.1145\/3538969.3538999","10.1145\/3538969"],"URL":"https:\/\/doi.org\/10.1145\/3538969.3538999","relation":{},"subject":[],"published":{"date-parts":[[2022,8,23]]},"assertion":[{"value":"2022-08-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}