Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
PHP upload security and php.ini
Old 02-22-2009, 04:05 PM PHP upload security and php.ini
Average Talker

Posts: 15
Trades: 0
Hello chaps I am currently making a php upload form for an admin page for pictures, videos and audio.

So far I have done a check size, mime type. I presume I will need to check file extensions, how would be the best way to go about this and also is there anything I can do in php.ini to stop malicious code being executed from an external source just incase something bad does get uploaded?

Anything else that I should keep in mind for the upload form?

Thanks
Luke
lukie_boy is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 02-22-2009, 06:24 PM Re: PHP upload security and php.ini
rogem002's Avatar
PHP Chap

Posts: 843
Name: Mike
Location: United Kingdom
Trades: 0
Make sure you make the file difficult to execute when it's accessed. I think you can force download via apache httaccess in certain folders.
__________________
My Blog/Site:
Please login or register to view this content. Registration is FREE
rogem002 is offline
Reply With Quote
View Public Profile Visit rogem002's homepage!
 
Old 02-22-2009, 06:41 PM Re: PHP upload security and php.ini
Average Talker

Posts: 15
Trades: 0
Ah right, the admin upload is there so the admin who doesn't know how to use FTP will be able to upload pic and then get access to them to use in which ever way he see fit.

using httacess can I make it so the file is just readable and I presume you can still parse audio and video to a webbpage so it's still viewable etc?
lukie_boy is offline
Reply With Quote
View Public Profile
 
Old 02-22-2009, 11:55 PM Re: PHP upload security and php.ini
lizciz's Avatar
Super Spam Talker

Posts: 807
Name: Mattias Nordahl
Location: Sweden
Trades: 0
I recently wrote such a script and got alot of help from this article
http://www.scanit.be/uploads/php-file-upload.pdf

And also a bit from this website (which I think is actually baesed on the above article, or at least refers to it.)
http://www.mysql-apache-php.com/fileupload-security.htm
lizciz is offline
Reply With Quote
View Public Profile Visit lizciz's homepage!
 
Old 02-23-2009, 07:21 AM Re: PHP upload security and php.ini
Average Talker

Posts: 15
Trades: 0
Quote:
Originally Posted by lizciz View Post
I recently wrote such a script and got alot of help from this article
http://www.scanit.be/uploads/php-file-upload.pdf

And also a bit from this website (which I think is actually baesed on the above article, or at least refers to it.)
http://www.mysql-apache-php.com/fileupload-security.htm
Brilliant thank you both, anyone else like to add their $0.02 ?

Last edited by lukie_boy; 02-23-2009 at 10:26 AM..
lukie_boy is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to PHP upload security and php.ini
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.22258 seconds with 12 queries