Author Topic: Allow visitors to upload images, is it secure?  (Read 4064 times)

0 Members and 1 Guest are viewing this topic.

Offline Oras

  • Pre-Newbie
  • Posts: 4
    • View Profile
Allow visitors to upload images, is it secure?
« on: April 10, 2006, 11:43:18 PM »
Hello,
I want to allow uploading pictures for visitors ... but I have a question, is it secure? i.e. what if a visitor uploaded a PHP file as .jpg? will the script recognize it? I searched the forum but didn't find answer.
Thank you for help

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Allow visitors to upload images, is it secure?
« Reply #1 on: April 11, 2006, 01:14:21 AM »
yes, 4images not only checks the extensions, but also the format of the common image files.
also, even if one somehow uploaded a renamed php file, there is no harm could do such file, because the server will not recognize it as php and will not execute it, unless the hacker got access to the server somehow...
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline waleed

  • Jr. Member
  • **
  • Posts: 71
    • View Profile
Re: Allow visitors to upload images, is it secure?
« Reply #2 on: April 12, 2006, 01:45:06 PM »
they hacked my gallery by uploading media files
they can upload .php as 3gp
dont ask me how ask them :mrgreen:

you better disable this option

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: Allow visitors to upload images, is it secure?
« Reply #3 on: April 12, 2006, 02:43:13 PM »
they hacked my gallery by uploading media files
they can upload .php as 3gp
dont ask me how ask them :mrgreen:
and they did it while you had all the bug fixes applyed? if so, then perhaps your letting them do it again to others by not reporting this to us!
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline Oras

  • Pre-Newbie
  • Posts: 4
    • View Profile
Re: Allow visitors to upload images, is it secure?
« Reply #4 on: April 12, 2006, 07:46:56 PM »
Thank you very much V@no for your reply