File Upload Size Restrction/Security

From: Date: Fri, 23 Jun 2000 15:00:12 +0000
Subject: File Upload Size Restrction/Security
Groups: php.general 
Request: Send a blank email to php-general+get-2803@lists.php.net to get a copy of this message
I am having a bit of a problem trying to make a file upload "safe". I have the MAX_FILE_SIZE hidden field set in my form, but if someone were to malisciously remove that and then post an enourmous file multiple times, it could cause the servers resources to be chewed up. I have the max file size directive in php.ini set to the default (2MB), but the server still seems to allow the whole file to arrive first, before applying that limit. In other words, these large maliscious files are getting there before they are removed because of the directive and still hogging resources while they are transferred. Am I wrong in how this is working? Is there a way to cut the file off midstream if it exceeds a certain size? Thanks in advance for any help/explanations. -- ls

« previous php.general (#2803) next »