Re: filtering uploaded files
| From: | A. S. Milnes | Date: | Wed, 30 Mar 2005 09:08:17 +0000 |
| Subject: | Re: filtering uploaded files | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-211850@lists.php.net to get a copy of this message | ||
On Wed, 2005-03-30 at 04:59, Richard Lynch wrote:
> Please reference their publications, if possible.
At hand immediately I have:-
PHP and MySQL Web Development 3rd edition by Luke Welling (Senior Web
Developer at MySQL) and Laura Thomson, published by
www.developers-library.com.
> It's just plain BAD security to trust this value for any real-world usage.
Surely it's part of the toolkit - you can filter out people sending
dangerous stuff if they are not that sophisticated. I would never want
to rely on one line of defence.
> And it's made meaningless by the browsers not standardizing what they send
> anyway.
It's an interesting point which I will need to investigate further.
Alan