Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Problem viewing image upload directory
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Problem viewing image upload directory

 Post Reply Post Reply
Author
dpyers View Drop Down
Senior Member
Senior Member


Joined: 12 May 2003
Status: Offline
Points: 3937
Post Options Post Options   Thanks (0) Thanks(0)   Quote dpyers Quote  Post ReplyReply Direct Link To This Post Topic: Problem viewing image upload directory
    Posted: 18 January 2006 at 3:30am
Noticed that when I upload an image, I can see file names uploaded by other people. The names don't mean a lot but if I click on one it previews. Seems like this could eat a lot of badwidth as people browse images.
 
Also, and more importantly, any directories in the image upload folder are viewable and browsable. The window should only display valid image extensions as set by the forum admin.

Lead me not into temptation... I know the short cut, follow me.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 18 January 2006 at 10:03am
This is part of the Web Wiz RTE version 3.

Files are first uploaded to a temp folder which is not viewable, once they have been checked out for malicous code, file size, etc. and included in a post are they placed in the public upload folder.

You can set what files and images are allowed to be viewed in the public upload folder by editing the RTE_setup.asp files, but by defualt only safe file types can be viewed.

The RTE file bowser will only allow you to move around the public upload folder and sub folders, and will only display allowd file and image types, so is quite secure.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 18 January 2006 at 10:05am
Sorry my mistake, I thought I had coded more security than that

The only file types viewable in the RTE file browser are those set by the forum admin in the upload section, so you don't need to edit the RTE_setup.asp file to put in allowed file types.

So yes only valid file types set by the forum admin are viewable.

The image and file upload should be much more secure than in previous versions, and security has been taken into account when coding it.


Edited by -boRg- - 18 January 2006 at 10:06am
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.