Re: File Upload security
by "Raj Bhaskar" <raj(at)lordofthemoon.com>
|
| Date: |
Fri, 27 Apr 2001 21:40:13 +0100 |
| To: |
hwg-basics(at)mail.hwg.org |
| In-Reply-To: |
|
| |
todo: View
Thread,
Original
|
|
Hi Tamera et al,
> According to what I've learned so far from studying php/MySQL -- to upload
> anything you have to give *nobody* directory permissions.
You are correct. I've just come accross this problem with PHP. As far
as I know, there is no real way around it. PHP exists as part of the
*nobody* group. The only way (slightly) around this is to ask your ISP to
add you to to the nobody group (if such a thing is possible -- I don't know
enough Unix to know whether it is or not) and then only make the
directory group writable, rather than world writable.
> Again, speaking from my /very, very/ limited experience, it's not that hard
> to rename an exe as a jpg and then get into the file and change it back if
> someone were truly dedicated.
You're always better checking the MIME type, rather than the file
extension. AFAIK, this would be harder to fake. Unfortunately, I haven't
got the PHP code with me right now that will check that, but I can get it
for you if you like.
HTH,
Raj.
--
__ __
| | | | Raj Bhaskar, University of Glasgow
|_ / |_ / E-Mail: raj(at)lordofthemoon.com
| \ | \ Home Page: http://lordofthemoon.com
| \ |__/
As far as Death was aware, the sole reason for any human association with
pigs and lambs was as a prelude to sausages and chops. Quite why they should
dress up for children's wallpaper as well was a mystery.
-- (Terry Pratchett, Hogfather)
HTML: hwg-basics mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.