Get support from Xavier Media
It is currently Sun Dec 08, 2013 3:36 pm

All times are UTC




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: File Upload Protection
PostPosted: Mon Oct 23, 2006 6:18 pm 

Points:
hi

hmmmm
i am look in our arabic website and read some of about upload files ...
anyway the problems i get it there is no one talk about how to protect the site when the file upload to mysite any one can help me in that and thankx for every one help me befor :)


Report this post
Top
  
Reply with quote  
 Post subject: Re: File Protection
PostPosted: Tue Oct 24, 2006 2:39 pm 

Points:
dragon tears wrote:
hi

hmmmm
i am look in our arabic website and read some of about upload files ...
anyway the problems i get it there is no one talk about how to protect the site when the file upload to mysite any one can help me in that and thankx for every one help me befor :)


Sorry, I am having a little trouble understanding you. Is this what you were saying?

dragon tears wrote:
hi

hmmmm
I was just looking at an Arabic website and I read some things about uploading files... anyway, it seems that no one talks about how to protect a site from dangerous file uploads. If anyone can help me in that I would really appreciate it, and thankx to everyone that helped me before :)


If that is what you want to know; I'm sorry but I can't answer that. To my knowledge, no human on earth has ever created a 100% secure file upload script. Now if you are uploading JPG's, GIF's, HTML, TXT, or other static files you don't really have to worry. Because the servers don't run those as scripts the just print them to the screen.

However, if you are uploading PHP, PERL, JAVA, etc... you will be putting your site at risk. because the server is set to RUN those files before sending them to the screen.

And there is more to this topic that I won't go into, but basically, no one teaches how to do it because no-one can. :wink:


Last edited by Guest on Tue Oct 24, 2006 2:50 pm, edited 1 time in total.

Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: Tue Oct 24, 2006 2:44 pm 

Points:
yea that what i mean but sorry my bad english


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: Tue Oct 24, 2006 2:52 pm 

Points:
So did that help?


Report this post
Top
  
Reply with quote  
 Post subject:
PostPosted: Tue Oct 24, 2006 3:03 pm 

Points:
ah okey let ask one thing..
if i am make uploading for all file all kind of files but i am force the
user to make it download and not show it like websites
filefront.com or rapidshar.com are that work to no one hack me ?!


Report this post
Top
  
Reply with quote  
 Post subject: Zipping
PostPosted: Tue Oct 24, 2006 3:26 pm 

Points:
Create a directory on your server that no one can access from the internet. For example if your website is located in on your server in this directory:

/www/html/yourwebsite/

Create a new directory OUTSIDE of your website that no one will be able to get to, like:

/www/yourwebsitesfiles/

Now no one will be able to type something like http://yourwebsite.com/yourwebsitefiles into their browser and get to the files from on the internet. The files will be hidden deep in your server.

Second, either limit the type of files to ZIP?ed/TAR archives (which is how filefront does it so that there is no danger of any bad scripts running) or rename all files to file-dot-extinction-dot-zip (like file.php.zip) so that the server THINKS that they are zipped archives. (You can find some really good tutorials on this in the tutorials section.)

Basically, if you only allow pictures or zipped files you are pretty much safe. If someone wants to upload a PHP file they will just have to ZIP it first!


Report this post
Top
  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC


Who is online

Registered users: No registered users


You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron

Portal » Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
[
SEO MOD © 2007 StarTrekGuide ]