Re: File Upload Size Restrction/Security
| From: | Rasmus Lerdorf | Date: | Fri, 23 Jun 2000 16:20:40 +0000 |
| Subject: | Re: File Upload Size Restrction/Security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2815@lists.php.net to get a copy of this message | ||
On Fri, 23 Jun 2000, it was written:
> I am having a bit of a problem trying to make a file upload "safe". I
> have the MAX_FILE_SIZE hidden field set in my form, but if someone were
> to malisciously remove that and then post an enourmous file multiple
> times, it could cause the servers resources to be chewed up.
>
> I have the max file size directive in php.ini set to the default (2MB),
> but the server still seems to allow the whole file to arrive first,
> before applying that limit. In other words, these large maliscious
> files are getting there before they are removed because of the
> directive and still hogging resources while they are transferred.
This should not be the case. Which version of PHP?
-Rasmus