Re: Security Issue Query.......
| From: | Simon Edwards | Date: | Thu, 07 Sep 2000 03:33:47 +0000 |
| Subject: | Re: Security Issue Query....... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15650@lists.php.net to get a copy of this message | ||
Randall Goguen wrote:
> Actualy I posted an article on this August 16
>
> Securing file uploads under PHP
> http://www.linuxguruz.org/z.php?id=320
>
> Contributed by Martin Sarsale (aka runa)
It's quite good except for a few things. You should not need removed
'..' strings from the file name. Without '/' chars they are harmless (I
*think*, what happens if you copy("file.txt","/tmp/..") ? anyone?)
Another thing that probably should have been mentioned is a server
configuration issue. Try uploading a php file instead of an image and
try viewing the recently uploaded file. Did you get the file or did the
server actually execute the php code? Lesson: Disable all cgi processing
etc in the file upload dir.
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990