View Single Post
Old September 1st, 2006, 1:12 PM   #18 (permalink)
twirp
DemonicAngel
Super #1
 
twirp's Avatar
 
Joined in Aug 2004
Lives in Wherever The World Takes Me
Hosted on Pass76
1,826 posts
Gave thanks: 26
Thanked 35 times
Quote:
Originally Posted by Skipdawg View Post
Awesome! It's just amazing what all hackers can do some times.
if you allow .rar, .zip, .tar, or basically any archive to be uploaded to your site, someone can upload malicious php code.
i.e. bleh.php.zip or bleh.php.rar (these files have nothing bad, just ask for a name, and then they say hello).
but as you can see the extension is .php.zip if it were changed to just .zip, the code won't execute.
so it's best to rename the file that is being uploaded, and posibly scan the file for coding...
__________________
You wear Vans so high school kids will think that you can skate. He wears Vans because he can skate. TwiRp wears Vans because they were on sale. Pass76 wants Vans.
twirp is offline   Reply With Quote