Re: Security Issue Query.......

From: Date: Thu, 07 Sep 2000 03:33:47 +0000
Subject: Re: Security Issue Query.......
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15650@lists.php.net to get a copy of this message
Randall Goguen wrote: > Actualy I posted an article on this August 16 > > Securing file uploads under PHP > http://www.linuxguruz.org/z.php?id=320 > > Contributed by Martin Sarsale (aka runa) It's quite good except for a few things. You should not need removed '..' strings from the file name. Without '/' chars they are harmless (I *think*, what happens if you copy("file.txt","/tmp/..") ? anyone?) Another thing that probably should have been mentioned is a server configuration issue. Try uploading a php file instead of an image and try viewing the recently uploaded file. Did you get the file or did the server actually execute the php code? Lesson: Disable all cgi processing etc in the file upload dir. -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990

« previous php.general (#15650) next »