Skip to content

Instantly share code, notes, and snippets.

@ConnerAiken
Last active June 7, 2017 21:04
Show Gist options
  • Save ConnerAiken/0ca46dfd3c18dbc82d33b919ac948ea6 to your computer and use it in GitHub Desktop.
Save ConnerAiken/0ca46dfd3c18dbc82d33b919ac948ea6 to your computer and use it in GitHub Desktop.
A collection of dangerous extensions to filter out of file uploads.
[
{
"ext":"adp",
"description":"Access Project (Microsoft)"
},
{
"ext":"app",
"description":"Executable Application"
},
{
"ext":"asp",
"description":"Active Server Page"
},
{
"ext":"bas",
"description":"BASIC Source Code"
},
{
"ext":"bat",
"description":"Batch Processing"
},
{
"ext":"cer",
"description":"Internet Security Certificate File"
},
{
"ext":"chm",
"description":"Compiled HTML Help"
},
{
"ext":"cmd",
"description":"DOS CP/M Command File, Command File for Windows NT"
},
{
"ext":"cnt",
"description":"Help file index"
},
{
"ext":"com",
"description":"Command"
},
{
"ext":"cpl",
"description":"Windows Control Panel Extension (Microsoft)"
},
{
"ext":"crt",
"description":"Certificate File"
},
{
"ext":"csh",
"description":"csh Script"
},
{
"ext":"der",
"description":"DER Encoded X509 Certificate File"
},
{
"ext":"exe",
"description":"Executable File"
},
{
"ext":"fxp",
"description":"FoxPro Compiled Source (Microsoft)"
},
{
"ext":"gadget",
"description":"Windows Vista gadget"
},
{
"ext":"hlp",
"description":"Windows Help File"
},
{
"ext":"hpj",
"description":"Project file used to create Windows Help File"
},
{
"ext":"hta",
"description":"Hypertext Application"
},
{
"ext":"inf",
"description":"Information or Setup File"
},
{
"ext":"ins",
"description":"IIS Internet Communications Settings (Microsoft)"
},
{
"ext":"isp",
"description":"IIS Internet Service Provider Settings (Microsoft)"
},
{
"ext":"its",
"description":"Internet Document Set, Internet Translation"
},
{
"ext":"js",
"description":"JavaScript Source Code"
},
{
"ext":"jse",
"description":"JScript Encoded Script File"
},
{
"ext":"ksh",
"description":"UNIX Shell Script"
},
{
"ext":"lnk",
"description":"Windows Shortcut File"
},
{
"ext":"mad",
"description":"Access Module Shortcut (Microsoft)"
},
{
"ext":"maf",
"description":"Access (Microsoft)"
},
{
"ext":"mag",
"description":"Access Diagram Shortcut (Microsoft)"
},
{
"ext":"mam",
"description":"Access Macro Shortcut (Microsoft)"
},
{
"ext":"maq",
"description":"Access Query Shortcut (Microsoft)"
},
{
"ext":"mar",
"description":"Access Report Shortcut (Microsoft)"
},
{
"ext":"mas",
"description":"Access Stored Procedures (Microsoft)"
},
{
"ext":"mat",
"description":"Access Table Shortcut (Microsoft)"
},
{
"ext":"mau",
"description":"Media Attachment Unit"
},
{
"ext":"mav",
"description":"Access View Shortcut (Microsoft)"
},
{
"ext":"maw",
"description":"Access Data Access Page (Microsoft)"
},
{
"ext":"mda",
"description":"Access Add-in (Microsoft), MDA Access 2 Workgroup (Microsoft)"
},
{
"ext":"mdb",
"description":"Access Application (Microsoft), MDB Access Database (Microsoft)"
},
{
"ext":"mde",
"description":"Access MDE Database File (Microsoft)"
},
{
"ext":"mdt",
"description":"Access Add-in Data (Microsoft)"
},
{
"ext":"mdw",
"description":"Access Workgroup Information (Microsoft)"
},
{
"ext":"mdz",
"description":"Access Wizard Template (Microsoft)"
},
{
"ext":"msc",
"description":"Microsoft Management Console Snap-in Control File (Microsoft)"
},
{
"ext":"msh",
"description":"Microsoft Shell"
},
{
"ext":"msh1",
"description":"Microsoft Shell"
},
{
"ext":"msh2",
"description":"Microsoft Shell"
},
{
"ext":"mshxml",
"description":"Microsoft Shell"
},
{
"ext":"msh1xml",
"description":"Microsoft Shell"
},
{
"ext":"msh2xml",
"description":"Microsoft Shell"
},
{
"ext":"msi",
"description":"Windows Installer File (Microsoft)"
},
{
"ext":"msp",
"description":"Windows Installer Update"
},
{
"ext":"mst",
"description":"Windows SDK Setup Transform Script"
},
{
"ext":"ops",
"description":"Office Profile Settings File"
},
{
"ext":"osd",
"description":"Application virtualized with Microsoft SoftGrid Sequencer"
},
{
"ext":"pcd",
"description":"Visual Test (Microsoft)"
},
{
"ext":"pif",
"description":"Windows Program Information File (Microsoft)"
},
{
"ext":"plg",
"description":"Developer Studio Build Log"
},
{
"ext":"prf",
"description":"Windows System File"
},
{
"ext":"prg",
"description":"Program File"
},
{
"ext":"pst",
"description":"MS Exchange Address Book File, Outlook Personal Folder File (Microsoft)"
},
{
"ext":"reg",
"description":"Registration Information/Key for W95/98, Registry Data File"
},
{
"ext":"scf",
"description":"Windows Explorer Command"
},
{
"ext":"scr",
"description":"Windows Screen Saver"
},
{
"ext":"sct",
"description":"Windows Script Component, Foxpro Screen (Microsoft)"
},
{
"ext":"shb",
"description":"Windows Shortcut into a Document"
},
{
"ext":"shs",
"description":"Shell Scrap Object File"
},
{
"ext":"ps1",
"description":"Windows PowerShell"
},
{
"ext":"ps1xml",
"description":"Windows PowerShell"
},
{
"ext":"ps2",
"description":"Windows PowerShell"
},
{
"ext":"ps2xml",
"description":"Windows PowerShell"
},
{
"ext":"psc1",
"description":"Windows PowerShell"
},
{
"ext":"psc2",
"description":"Windows PowerShell"
},
{
"ext":"tmp",
"description":"Temporary File/Folder"
},
{
"ext":"url",
"description":"Internet Location"
},
{
"ext":"vb",
"description":"VBScript File or Any VisualBasic Source"
},
{
"ext":"vbe",
"description":"VBScript Encoded Script File"
},
{
"ext":"vbp",
"description":"Visual Basic project file"
},
{
"ext":"vbs",
"description":"VBScript Script File, Visual Basic for Applications Script"
},
{
"ext":"vsmacros",
"description":"Visual Studio .NET Binary-based Macro Project (Microsoft)"
},
{
"ext":"vsw",
"description":"Visio Workspace File (Microsoft)"
},
{
"ext":"ws",
"description":"Windows Script File"
},
{
"ext":"wsc",
"description":"Windows Script Component"
},
{
"ext":"wsf",
"description":"Windows Script File"
},
{
"ext":"wsh",
"description":"Windows Script Host Settings File"
},
{
"ext":"xnk",
"description":"Exchange Public Folder Shortcut"
},
{
"ext":"ade",
"description":"ADC Audio File"
},
{
"ext":"cla   ",
"description":"Java class File"
},
{
"ext":"class",
"description":"Java class File"
},
{
"ext":"grp",
"description":"Microsoft Widows Program Group"
},
{
"ext":"jar",
"description":"Compressed archive file package for Java classes and data"
},
{
"ext":"mcf",
"description":"MMS Composer File"
},
{
"ext":"ocx",
"description":"ActiveX Control file"
},
{
"ext":"pl",
"description":"Perl script language source code"
},
{
"ext":"xbap",
"description":"Silverlight Application Package"
}
]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment