Re: JPEG Upload
| From: | Sanford Whiteman | Date: | Sat, 05 May 2012 22:16:23 +0000 |
| Subject: | Re: JPEG Upload | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60481@lists.php.net to get a copy of this message | ||
> Moreover, that still doesn't protect you, as it would be possible to
> make a valid image where the payload happened in the image data...
Agreed. But sanitizing input by silently removing blocks of data your
users rightfully expect to be preserved? That's egregious, even if it
"worked."
(Like many such discussions, I almost can't believe we're having this
one... I mean, executing images is just not normal whether or not you
can "bear the (performance) cost." Who is doing this on purpose?)
-- S.