HTTP file servers range from a web server's directory autoindex (Apache, nginx) to dedicated software like HTTP File Server (HFS) and filebrowser. They expose files over HTTP and often allow uploads. Attacks disclose files through listing and traversal, turn upload into code execution, and exploit named flaws in the server software itself.
Subtopics#
- Directory listing: enumerating exposed files.
- Path traversal: reading outside the served root.
- File upload to RCE: turning upload into execution.
- Known server exploits: named RCE in file-server software.