Re: File Upload security

by "Raj Bhaskar" <raj(at)lordofthemoon.com>

 Date:  Fri, 27 Apr 2001 21:40:13 +0100
 To:  hwg-basics(at)mail.hwg.org
 In-Reply-To: 
  todo: View Thread, Original
Hi Tamera et al,

> According to what I've learned so far from studying php/MySQL -- to upload
> anything you have to give *nobody* directory permissions. 

You are correct.  I've just come accross this problem with PHP.  As far 
as I know, there is no real way around it.  PHP exists as part of the 
*nobody* group.  The only way (slightly) around this is to ask your ISP to 
add you to to the nobody group (if such a thing is possible -- I don't know 
enough Unix to know whether it is or not) and then only make the 
directory group writable, rather than world writable.

> Again, speaking from my /very, very/ limited experience, it's not that hard
> to rename an exe as a jpg and then get into the file and change it back if
> someone were truly dedicated.

You're always better checking the MIME type, rather than the file 
extension.  AFAIK, this would be harder to fake.  Unfortunately, I haven't 
got the PHP code with me right now that will check that, but I can get it 
for you if you like.

HTH,
Raj.
-- 
__        __
|   |	|   |   Raj Bhaskar, University of Glasgow
|_ / 	|_ /    E-Mail: raj(at)lordofthemoon.com
|   \	|   \   Home Page: http://lordofthemoon.com
|    \	|__/   
As far as Death was aware, the sole reason for any human association with
pigs and lambs was as a prelude to sausages and chops.  Quite why they should
dress up for children's wallpaper as well was a mystery.
	-- (Terry Pratchett, Hogfather)

HTML: hwg-basics mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.