File Upload Size Restrction/Security
| From: | Unknown Sender | Date: | Fri, 23 Jun 2000 15:00:12 +0000 |
| Subject: | File Upload Size Restrction/Security | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-2803@lists.php.net to get a copy of this message | ||
I am having a bit of a problem trying to make a file upload "safe". I
have the MAX_FILE_SIZE hidden field set in my form, but if someone were
to malisciously remove that and then post an enourmous file multiple
times, it could cause the servers resources to be chewed up.
I have the max file size directive in php.ini set to the default (2MB),
but the server still seems to allow the whole file to arrive first,
before applying that limit. In other words, these large maliscious
files are getting there before they are removed because of the
directive and still hogging resources while they are transferred.
Am I wrong in how this is working? Is there a way to cut the file off
midstream if it exceeds a certain size?
Thanks in advance for any help/explanations.
--
ls