|
|
Joined: May 1999
Posts: 1,715
Addict
|
Addict
Joined: May 1999
Posts: 1,715 |
I used to allow uploading of php-files (haven't for quite a while though) and I just saw a guy who uploaded a couple of different scripts trying to read my config file. Didn't work though, since it's outside the web directory, and it's not possible to run php scripts in the files directory. The guy even tried to make the php files into some binary format to be able to make it run (still didn't work of course).
This happened quite a few months ago, but I haven't seen it until now... The stupid idiot didn't even clean up after himself (like the last guy I found, who at least tried =P), the files are still there.
These damn script-kiddies are everywhere... Following the security instructions from infopop is a very good idea.
|
|
|
|
Joined: Jun 2002
Posts: 303
Enthusiast
|
Enthusiast
Joined: Jun 2002
Posts: 303 |
I only allow .gif, .jpg and .png file uploads. Pardon my ignorance, but can malicious programming be embedded in these file formats?
|
|
|
|
Joined: Aug 2002
Posts: 1,191
Kahuna
|
Kahuna
Joined: Aug 2002
Posts: 1,191 |
Interesting topic. As a matter of fact I was wondering what could happen if you have HTML enabled and one of your users posts something with HTML code embedded in it to retrieve information or to cause damage. Would that work? If yes then surely disabling HTML would solve the problem....
Warm regards
Nikos
Nikos
|
|
|
|
Joined: Nov 2001
Posts: 10,369
I type Like navaho
|
I type Like navaho
Joined: Nov 2001
Posts: 10,369 |
Yeah, Running with HTML on is a bad idea. 
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
Posts: 69
Joined: January 2001
|
|
Forums63
Topics37,575
Posts293,931
Members13,823
|
Most Online6,139 Sep 21st, 2024
|
|
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
|
|
|
|
|