note 40569 added to function.move-uploaded-file
| From: | sauronatnospamonmorannondotorg at rn2 dot php dot net | Date: | Mon, 08 Mar 2004 10:20:35 +0000 |
| Subject: | note 40569 added to function.move-uploaded-file | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-66424@lists.php.net to get a copy of this message | ||
An extension only does not really tell you what type of file it really is. I can easily rename a
.jpg file to a .zip file and make the server think it is a ZIP file with webmaster
kobrasrealm's code.
A better way is to use the Linux utility "file" to determine the file type. Although
I'm aware that some users might use Windows on their webservers, I thought it's worth
mentioning the utility here. Using the backtick operators and preg_matches on the output, you can
easily determine the file type safely, and fix the extension when necessary.
----
Manual Page -- http://www.php.net/manual/en/function.move-uploaded-file.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+40569
Delete -- http://master.php.net/manage/user-notes.php?action=delete+40569&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+40569&report=yes
Search -- http://master.php.net/manage/user-notes.php