doz95923 2014-05-10 15:40
浏览 36

拒绝上传非图像文件类型,仅允许上传目录中的特定.php文件

I'm not very good when it comes to .htaccess rules so I'm seeking your help.

I'm trying to find a set of rules that would enhance the security of my PHP app in the following manners:

  1. Deny upload of all file types except for images [jpg, png, gif] and docs [pdf, doc, docx]
  2. Deny access to all [php, php3] files except for index.php, image.php in folder /uploads and all sub folders

PS: My goal is to deny the upload and direct access to malicious uploaders even if they find away to bypass my uploads handler. The reason I'm seeking a solution with .htaccess is because rewriting the code would be very time consuming as the app has been deployed on a number of websites.

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 虚幻5 UE美术毛发渲染
    • ¥15 CVRP 图论 物流运输优化
    • ¥15 Tableau online 嵌入ppt失败
    • ¥100 支付宝网页转账系统不识别账号
    • ¥15 基于单片机的靶位控制系统
    • ¥15 真我手机蓝牙传输进度消息被关闭了,怎么打开?(关键词-消息通知)
    • ¥15 下图接收小电路,谁知道原理
    • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
    • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
    • ¥15 手机接入宽带网线,如何释放宽带全部速度