RE: [PHP] Whats wrong here?

From: Date: Fri, 08 Sep 2000 19:24:50 +0000
Subject: RE: [PHP] Whats wrong here?
Groups: php.general 
Request: Send a blank email to php-general+get-15939@lists.php.net to get a copy of this message
Shane, Okay... Now that I have a better understand of what you are trying to accomplish I want to give you a little bit of tutorial on how to do this. Uploading files to a web server is a great feature and function of PHP HOWEVER, it can be extermly dangerous for a webservers overall security. Case in point I have a friend that runs a pretty popular website with a PHP/MySQL engine. He is allowing people to upload pictures for their profiles. I discovered (the hacker in me) that you could upload a PHP file that would be placed in the server root. I then called that file from my browser. The file was designed to go out and grab the /etc/passwd file and then mail a copy to myself and to him with a message saying "GOTCHA!" He closed the loop hole shortly after that by placing checks on the file name and file type. So here is a slimmed down version of what you want to do. This uses the variable name $picture that comes from an HTML form. <? $timestamp = time(); $image= $timestamp.$picture_name; exec("mv $picture /path/to/html/dir/$image"); //You must use linux paths ?> <img src="/images/<?= $image ?>"> <? //You must use httpd server paths ?> This of course will prevent two images named the same from overwriting each other... There are other things you need to look out for like names with spaces... But that should get you on your way... HTH Tom Walsh http://www.designgeek.com > Yes, it is a form field. I actually have a form that is prone > to user error. > I have an upload file field and then a file name field. This > allows the end > user to screw up, but with my limited php ability I was just > trying to get > something to work. > > The end goal is to upload a file to a certain directory and retain the > original filename.

« previous php.general (#15939) next »