dongzhan0624 2012-11-15 16:26
浏览 110
已采纳

PHP文件上传代码注入[重复]

Possible Duplicate:
Stop people uploading malicious PHP files via forms

i found a way to clean the images from injected code by adding a very small transparent image to the uploaded image using PHP GD Library this will destroy the injected code (is there a better way ?).

but what about the other extensions if someone injected a code in a text file or whatever extension what can the attacker do in my server and how to prevent this type of code injection.

i'm writing a file upload script and i'm so confused in the security i searched a lot but nothing really helped me.

your help is highly appreciated.

  • 写回答

1条回答 默认 最新

  • drxvjnx58751 2012-11-15 16:38
    关注

    You can set the file permissions of all uploaded files to read using CHMOD like

    <?php
      $filename = 'path/to/your/file.zip';
      chmod($filename, '744');
    ?>
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 Oracle中如何从clob类型截取特定字符串后面的字符
  • ¥15 想通过pywinauto自动电机应用程序按钮,但是找不到应用程序按钮信息
  • ¥15 如何在炒股软件中,爬到我想看的日k线
  • ¥15 seatunnel 怎么配置Elasticsearch
  • ¥15 PSCAD安装问题 ERROR: Visual Studio 2013, 2015, 2017 or 2019 is not found in the system.
  • ¥15 (标签-MATLAB|关键词-多址)
  • ¥15 关于#MATLAB#的问题,如何解决?(相关搜索:信噪比,系统容量)
  • ¥500 52810做蓝牙接受端
  • ¥15 基于PLC的三轴机械手程序
  • ¥15 多址通信方式的抗噪声性能和系统容量对比