Welcome Guest, Not a member yet? Register   Sign In
best way to upload and rename an image
#10

[eluser]Rick Jolly[/eluser]
[quote author="llbbl" date="1193190836"][quote author="FuzzyJared" date="1193190081"]that does make sense.
[/quote]

if you want your server hacked use that code.

1) don't let the user access the images via the same name or similar name as the original file name.
2) upload the images outside the web root
3) use a php script to view the images

If you can't do 2 or 3 than:

4) check for file extensions
5) use GD to verify it is an image
6) upload the images to a subdomain with php and cgi disabled[/quote]

llbbl, don't attack me for answering the question. Upload security was not part of the question and that would have made a very long answer.
1) how is img_1.jpg in any way similar to the original file name?
2) "tmp/" IS outside the web root and I intentionally didn't specify where "uploads/" was. It could, and in most cases should, be outside the web root, but that is up to FuzzyJared.
3) See #2.

Final thought:
Posting a link to file security, although important, does nothing to answer FuzzyJared's question. For all you know from what has been said, FuzzyJared and I co-wrote that article.


Messages In This Thread
best way to upload and rename an image - by El Forum - 10-23-2007, 01:54 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:34 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:36 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:40 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:41 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:48 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:53 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 02:55 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 03:02 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 03:04 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 03:16 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 03:29 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 04:13 PM
best way to upload and rename an image - by El Forum - 10-23-2007, 07:49 PM
best way to upload and rename an image - by El Forum - 10-24-2007, 10:49 AM
best way to upload and rename an image - by El Forum - 10-24-2007, 12:17 PM
best way to upload and rename an image - by El Forum - 10-24-2007, 02:31 PM
best way to upload and rename an image - by El Forum - 10-24-2007, 03:29 PM
best way to upload and rename an image - by El Forum - 10-24-2007, 03:44 PM
best way to upload and rename an image - by El Forum - 10-30-2007, 04:57 PM
best way to upload and rename an image - by El Forum - 03-22-2008, 02:18 AM
best way to upload and rename an image - by El Forum - 03-24-2008, 10:51 AM



Theme © iAndrew 2016 - Forum software by © MyBB