In most web applications, uploading harmful files is allowed with the precautions taken in the file upload section. One of these protection methods is file hash control mechanisms. However, in this presentation, you will see how a file can be added to the system and how the code can run remotely with hash manipulation, how a user can become an authorized user in the system, and how to increase the privileges of the seized application user on a popular application. You will be able to see both a new method and a fresh 0Day as part of the presentation.