Re: OT - Public Upload Security
This WebDNA talk-list message is from 2002
It keeps the original formatting.
numero = 41476
interpreted = N
texte = Hi Alisha,On Friday, July 12, 2002, at 05:59 PM, Alisha Outridge wrote:> When an upload takes place from a user on your public site - how do you > other programmers make sure it is not something dangerous?Good question :)> I am specifically interested in the uploading of image files at this point > but all media would be useful. Currently I am checking the width and > height of the uploaded image when it is put on my server and before it is > uploaded it is bounced back if it does not have a .gif or .jpg extension.I am about ready to allow my users to upload images as well. I will check as you are doing now as well. I will also be using the [shell] context (ok, I am now on linux, but you should be able to do this with applescript as well) to call the anti-virus program I just bought to check the upload folder prior to doing any further processing.> Do I need some sort of third party software to scan it? I run the platform > MacOS 9 and use Webstar 4.0 with WebCat 3.0.I would look for an anti-virus tool that you can control via applescript. The things I think would be important are the ability to specify the folder and the ability to get some sort of results back - or, that the anti-virus program will move the file for you to a safe folder.> Alisha Outridge> Spec Simple, Inc.> Where the World of Design Connects...Dale-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list
.To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Hi Alisha,On Friday, July 12, 2002, at 05:59 PM, Alisha Outridge wrote:> When an upload takes place from a user on your public site - how do you > other programmers make sure it is not something dangerous?Good question :)> I am specifically interested in the uploading of image files at this point > but all media would be useful. Currently I am checking the width and > height of the uploaded image when it is put on my server and before it is > uploaded it is bounced back if it does not have a .gif or .jpg extension.I am about ready to allow my users to upload images as well. I will check as you are doing now as well. I will also be using the [shell] context (ok, I am now on linux, but you should be able to do this with applescript as well) to call the anti-virus program I just bought to check the upload folder prior to doing any further processing.> Do I need some sort of third party software to scan it? I run the platform > MacOS 9 and use Webstar 4.0 with WebCat 3.0.I would look for an anti-virus tool that you can control via applescript. The things I think would be important are the ability to specify the folder and the ability to get some sort of results back - or, that the anti-virus program will move the file for you to a safe folder.> Alisha Outridge> Spec Simple, Inc.> Where the World of Design Connects...Dale-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/
dale's stuff
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
[OT] Domain Name Scam (2000)
Before I Can Begin . . . (1998)
Express Lane (2000)
system crashes, event log (1997)
Unexpected error (1997)
Execute Applescript (1997)
Major Security Hole IIS NT (1998)
RAM variables (1997)
[WebDNA] Create a cryptographic Mac key... (2016)
Email...Thanks (1997)
Logging purchases (1997)
no global [username] or [password] displayed ... (1997)
Web Developer Product Awards (1997)
multi-paragraph fields (1997)
[Sum] function? (1997)
WebCat2 Append problem (B14Macacgi) (1997)
WebMerchant 1.6 and SHTML (1997)
Multi-processor Mac info ... (1997)
PCS Frames (1997)
remotely add + sign (1997)