Re: JPEG Upload
| From: | Paul Reinheimer | Date: | Sun, 06 May 2012 00:40:22 +0000 |
| Subject: | Re: JPEG Upload | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-60484@lists.php.net to get a copy of this message | ||
I dealt with jpegs with injected metadata quite a bit at a previous employer.
In the end we ended up confirming the file was a proper image with the
filetype functions, then stripping the metadata using some command
line tools, and finally using a blacklist for key strings (like <?php)
that could show up in the file.
paul