RE: safety upload

From: Albert Pascual (AlbertPascual_at_discussions.microsoft.com)
Date: 02/25/05


Date: Fri, 25 Feb 2005 08:53:06 -0800

Check the file extension and the size when uploading it, then move it to
another directory and rename it.

"Mango" wrote:

> Hi friends,
>
> Please help me.
>
> I want to realize upload on .jpg files in my web server and I am not sure
> haw to protect it. I mean, when the user do upload I have to give him/her
> write privilege, I am not sure is this dangerous.
>
> Is my server become more vulnerable?
>
> How to protect it?
>
> I will appreciate any help
>
>
>



Relevant Pages

  • Re: Can not download DWT-files from document libraries
    ... If I try to upload a dll-file, ... It's so frustrating that dwt-files doesn't work in the same way! ... It seems that SPS also blocks the file extension in some way. ...
    (microsoft.public.sharepoint.portalserver)
  • Re: unable to upload
    ... Reed's employment agancy, ... I get an error message saying Invalid ... So the file extension in this case is "*.docx". ... to upload that newly saved document (which will have the *.doc extension ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Checking if an image
    ... > I have an ASP.NET where users can upload images to the server. ... > implemented business logic that checks the file extension of the files ... > occured to me that a devious user might simply give some non image (Like ...
    (microsoft.public.dotnet.framework.drawing)
  • [Full-disclosure] Geeklog <= v1.6.0sr2 - Remote File Upload
    ... Geeklog <= v1.6.0sr2 - Remote File Upload ... Geeklog has several options to upload images. ... based on file extension. ... Executable javascript can easily be uploaded. ...
    (Full-Disclosure)
  • Re: Limiting fileupload file types
    ... done on the client-side using JavaScript. ... JavaScript function that checks the "value" attribute of the "input ... check the file extension. ... Currently site visitors can upload any type of file. ...
    (microsoft.public.frontpage.programming)