Re: Re: Security Concerns with Uploaded Images:

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, May 23, 2006 3:45 am, Rory Browne wrote:
>> Use the unix command "file" to determiner what file you have.
>> I have had the same problem...
>
> Don't depend on it.

http://php.net/getimagesize

would be slightly better, as it tries to dig out width/height and
number of colors for any given format, plus other fun stuff for some
formats.

So they'd have to hack MORE of a file and make it look kosher enough
to fool that...

You STILL ought to put the images  OUTSIDE the webtree and use PHP to
readfile them so they can never get executed by remote visitor, imho.

-- 
Like Music?
http://l-i-e.com/artists.htm

-- 
PHP General Mailing List (http://www.php.net/)
To unsubscribe, visit: http://www.php.net/unsub.php


[Index of Archives]     [PHP Home]     [Apache Users]     [PHP on Windows]     [Kernel Newbies]     [PHP Install]     [PHP Classes]     [Pear]     [Postgresql]     [Postgresql PHP]     [PHP on Windows]     [PHP Database Programming]     [PHP SOAP]

  Powered by Linux