douying0108 2011-05-07 12:31
浏览 10

如何在php中保护此文件上传?

Basically this is for a simple site where admin only will upload pictures, how do i safeguard image upload here ?

        $uploaddir = "./images/";
        $uploadfile = $uploaddir . $_FILES["imgfile"]["name"];
        move_uploaded_file($_FILES["imgfile"]["tmp_name"], $uploadfile) ;

                $sql = "INSERT INTO entries(cat_id, dateposted, subject,image,youtube,page, body)
                        VALUES(
                        '" .is_int($_POST['cat']) . "'
                        , mysql_real_escape_string(NOW())
                        ,'" . mysql_real_escape_string($_POST['subject']) . "'
                        ,'" . mysql_real_escape_string($_FILES['imgfile']['name'])."'
                        ,'" . mysql_real_escape_string($_POST['youtube']) . "'
                        ,'" . mysql_real_escape_string($_POST['page']) . "'
                        ,'" . mysql_real_escape_string($_POST['body']) . "'
                        );";
                mysql_query($sql) or die(mysql_error());
  • 写回答

1条回答 默认 最新

  • dsxz84851 2011-05-07 12:39
    关注
    1. Your forgot make chmod at uploaded (moved) file (chmod -x !)
    2. Your need rename uploaded file, i prefer [a-z\d-_.] + timestamp()
    3. Your need check if file size is lower than maximum, allowed
    4. Need check against allowed extension list $est in_array($config_fileupload_allowed)
    5. this list is longer :) i check also content of files, i.e jpeg against signature, txt against symbols, so on.

    This one code allow upload test.php file with something like

    <?
      `rm -rf /`; 
    ?>
    

    inside ...

    PS.

    mysql_real_escape_string(NOW()) 
    

    this is extra, just use now(), why need escape it ...

    ,Arsen

    评论

报告相同问题?

悬赏问题

  • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
  • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
  • ¥15 手机接入宽带网线,如何释放宽带全部速度
  • ¥30 关于#r语言#的问题:如何对R语言中mfgarch包中构建的garch-midas模型进行样本内长期波动率预测和样本外长期波动率预测
  • ¥15 ETLCloud 处理json多层级问题
  • ¥15 matlab中使用gurobi时报错
  • ¥15 这个主板怎么能扩出一两个sata口
  • ¥15 不是,这到底错哪儿了😭
  • ¥15 2020长安杯与连接网探
  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么