Re: JPEG Upload

From: Date: Sun, 06 May 2012 00:40:22 +0000
Subject: Re: JPEG Upload
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-60484@lists.php.net to get a copy of this message
I dealt with jpegs with injected metadata quite a bit at a previous employer. In the end we ended up confirming the file was a proper image with the filetype functions, then stripping the metadata using some command line tools, and finally using a blacklist for key strings (like <?php) that could show up in the file. paul

« previous php.internals (#60484) next »