Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Potential security hole?
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Potential security hole?

 Post Reply Post Reply
Author
adawg View Drop Down
Groupie
Groupie
Avatar

Joined: 10 February 2003
Status: Offline
Points: 42
Post Options Post Options   Thanks (0) Thanks(0)   Quote adawg Quote  Post ReplyReply Direct Link To This Post Topic: Potential security hole?
    Posted: 17 April 2003 at 3:42pm

Taken directly from one of my users:

When someone tries to upload a file that is not allowed, you should just tell them that file is not allowed. If you give them the files that are allowed, then all someone has to do is masquerade his file as any of the accepted file types.

 

Back to Top
Dergal View Drop Down
Groupie
Groupie


Joined: 21 January 2002
Location: United Kingdom
Status: Offline
Points: 67
Post Options Post Options   Thanks (0) Thanks(0)   Quote Dergal Quote  Post ReplyReply Direct Link To This Post Posted: 18 April 2003 at 5:51am

 

And do what with it?

the only certain file extensions are executed / processed... so if I upload a potentially dangerous ASP script and call it .jpg it will NOT be run... (unless there is something I don't know about)

Gerry

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.