RE: [PHP] Uploading Files
| From: | Tom Walsh | Date: | Wed, 27 Sep 2000 18:58:41 +0000 |
| Subject: | RE: [PHP] Uploading Files | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17774@lists.php.net to get a copy of this message | ||
There sure are... Anytime you are uploading files from an end user you can
have all sorts of problems. One that typically happens because alot of
people do not think this through is... Taking a graphic file (or what they
assume to be a graphic file) and placing it in the web structure.
Case in point: An associate of mine is running a server with just such a
feature in PHP. I took it upon myself to create a PHP script and uploaded it
to the server. Then pointed my browser to it and it excuted (due to the fact
he had no mime checking or rename feature on the files that were uploaded).
When I pointed my browser to it, it went out and grabbed his passwd file and
mailed a copy to him.
He fixed the hole in under 10 minutes. :-)
Use caution young Jedi.
Tom Walsh
http://www.designgeek.com
> -----Original Message-----
> From: Adam Plocher [mailto:aplocher@erepublic.com]
> Sent: Wednesday, September 27, 2000 12:59 PM
> To: 'php-general@lists.php.net'
> Subject: [PHP] Uploading Files
>
>
> Are there any security risks involved when allowing people to
> upload a file
> over the web with PHP?
>
> Thanks,
> Adam Plocher
>