Welcome Guest, Not a member yet? Register   Sign In
Image Uploading security: URL, normal upload or Gravatar??
#1

[eluser]jojo777[/eluser]
Hi everyone!

Well i was thinking in the best way to stablish the way users sets their avatar for a web page. So first i had thought about getting the avatar from an existing url.

So I did it, using file gets contents and with curl if get contents wasnt on. But then i read about inserting malicious php script in jpg images.

So i was wondering if that's possible if I create a common CI upload form and users uploads their images to my web. !?¿
The alternative is using the Gravatar helper but i would like to offer users choose between one of them.

Any suggestions?

Thanks.
#2

[eluser]jojo777[/eluser]
So, nobody can give me any tip??

I was trying to make secure image uploading against images with php code inside them.
Then I did try with a image with some php inside, it worked, the image was uploaded with its annoying php code, but the thumbnail of the same image was all clean!

So, how can I transform the upload image, clone it or whatever to be 100% secure it isnt with any code inside??

Thanks a lot!




Theme © iAndrew 2016 - Forum software by © MyBB