RE: [PHP] Whats wrong here?
| From: | Tom Walsh | Date: | Fri, 08 Sep 2000 19:24:50 +0000 |
| Subject: | RE: [PHP] Whats wrong here? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-15939@lists.php.net to get a copy of this message | ||
Shane,
Okay... Now that I have a better understand of what you are trying to
accomplish I want to give you a little bit of tutorial on how to do this.
Uploading files to a web server is a great feature and function of PHP
HOWEVER, it can be extermly dangerous for a webservers overall security.
Case in point I have a friend that runs a pretty popular website with a
PHP/MySQL engine. He is allowing people to upload pictures for their
profiles. I discovered (the hacker in me) that you could upload a PHP file
that would be placed in the server root. I then called that file from my
browser. The file was designed to go out and grab the /etc/passwd file and
then mail a copy to myself and to him with a message saying "GOTCHA!" He
closed the loop hole shortly after that by placing checks on the file name
and file type.
So here is a slimmed down version of what you want to do.
This uses the variable name $picture that comes from an HTML form.
<?
$timestamp = time();
$image= $timestamp.$picture_name;
exec("mv $picture /path/to/html/dir/$image"); //You must use linux paths
?> <img src="/images/<?= $image ?>"> <? //You must use httpd server
paths ?>
This of course will prevent two images named the same from overwriting each
other... There are other things you need to look out for like names with
spaces... But that should get you on your way...
HTH
Tom Walsh
http://www.designgeek.com
> Yes, it is a form field. I actually have a form that is prone
> to user error.
> I have an upload file field and then a file name field. This
> allows the end
> user to screw up, but with my limited php ability I was just
> trying to get
> something to work.
>
> The end goal is to upload a file to a certain directory and retain the
> original filename.