Re: Re: verify file types when uploading to server...
| From: | Miguel Cruz | Date: | Thu, 18 Apr 2002 18:30:05 +0000 |
| Subject: | Re: Re: verify file types when uploading to server... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-93575@lists.php.net to get a copy of this message | ||
Unix systems have a program called 'file' that will look inside a file to
try to figure out what sort of data it contains, regardless of how it's
named. Generally it just looks at the first few bytes for a telltale
fingerprint but there are all sorts of rules for different file types.
This is similar to the mechanism IE uses to override server-sent MIME
types.
You can send the path of your uploaded file to the 'file' command and
parse the output to see what sort of data appears to be contained within.
Try it on the command line to see what sort of output it produces for
various file types.
miguel
On Thu, 18 Apr 2002, jas wrote:
> Could you explain that a little more?
> thanks,
> Jas
>
> "Miguel Cruz" <mnc@stoic.net> wrote in message
> news:Pine.LNX.4.44.0204181253310.29157-100000@stoic.net...
> > Not sure what you're tring to achieve, but that only checks the file's
> > name. You might want to use file (man 1 file) to verify that it actually
> > is a JPEG, since people can put malicious data into a file named xxx.jpg
> > and perhaps fool IE into doing bad things.
> >
> > miguel
> >
> > On Wed, 17 Apr 2002, jas wrote:
> >
> > > Oops... Hope this helps others, here is what I did:
> > > // This is your form...
> > > <form name="img1" method="post" action="done.php"
> > > target="box"
> > > enctype="multipart/form-data">
> > > <input type="file" name="img1" size="25">
> > > <br><br>
> > > <input type="submit" name="Submit"
> > > value="save">
> > >
> > > <input type="reset" name="reset"
> > > value="reset">
> > > </form>
> > > // this is the script to upload the file
> > > // Note: if you want to only upload certain file types... change the
> > > eregi('.jpg$ sting to whatever your file extension should be
> > > // Also the directory in question needs permissions set to 755 for it to
> > > work.
> > > <?php
> > > if ($img1_name != "" && eregi('.jpg$', $img1_name)) {
> > > @copy("$img1", "/path/to/directory/$img1_name") or die
> > > ("Could not
> upload
> > > file, please try again after making sure the file is less than 2mb in
> size
> > > and the file name correct");
> > > } else {
> > > die("No file selected for upload, or the file was not the correct
> type.
> > > Please only upload .jpg files.");
> > > }
> > > ?>
> > >
> > > "Michael Andersson" <chrazy@hotpop.com> wrote in message
> > > news:20020418101359.53504.qmail@pb1.pair.com...
> > > > Maybe you want to share with the rest of us, or at least me how you
> did
> > > it?
> > > > :)
> > > >
> > > > /Micke
> > > > "Jas" <jlgerfen@hotmail.com> skrev i meddelandet
> > > > news:20020417220530.59416.qmail@pb1.pair.com...
> > > > > Nevermind... =)
> > > > > "Jas" <jlgerfen@hotmail.com> wrote in message
> > > > >
> > > > > news:20020417214352.28025.qmail@pb1.pair.com...
> > > > > > I am wondering if any one has a good idea on how to do checking
> based
> > > on
> > > > a
> > > > > > files extension, what I am trying to accomplish is to be able to
> > > upload
> > > > > > files to a webserver however I only want to have .jpg files
> uploaded.
> > > > If
> > > > > > anyone has a good way to do this please share.
> > > > > > Thanks in advance,
> > > > > > Jas
> > > > > >
> > > > > >
> > > > >
> > > > >
> > > >
> > > >
> > >
> > >
> > >
> > >
> >
>
>
>
>