Richard, a penetration tester was asked to assess a web application. During the assessment, he discovered a file upload field where users can upload their profile pictures. While scanning the page for vulnerabilities, Richard found a file upload exploit on the website. Richard wants to test the web application by uploading a malicious PHP shell, but the web page denied the file upload. Trying to get around the security, Richard added the `˜jpg' extension to the end of the file. The new
[1]
successfully upload the PHP shell.
Which of the following techniques has Richard implemented to upload the PHP shell?