Freelancers Network
 
skill list top cap
Homepage
Join the Freelancer's Network
Update your details
Find a freelancer
Post a project
Find a project
Projects Archive
Post a job
Find a job
Jobs Archive
See Dan's Pages
See Andy's Pages
Link to this site
Resources
Join/Leave Forum
Forum Messages
+Additions+ Adverts
Advertising
Contact Us
Subscribe to our newsletter - enter your email address and hit return
Freelancers.net is owned and operated by Andy Stowell and Dan Winchester
skill list end cap
guru web hostcom

Find me again on Freelancers.net

RE: FN-FORUM: file size /type best practice

date posted 29th January 2007 12:23

parsing the filename for the correct extension is a good idea as a basic check, but you really need to make sure that whats being uploaded really is an image and not a script with a image file extension. Mime-type checks are one way but they can be spoofed. I'd use something like exif_imagetype() which is a bit better at making sure an image is indeed an image.

see here: http://devzone.zend.com/manual/view/page/function.exif-imagetype.html

doing it in JS probably is possible but when you're dealing with a function where someone could potentially upload harmful files its probably best not to let them see the code that does the checks!




>
>As part of an image upload script, I want to limit the file types and max
>sizes (file size not dimensions)
>
>Obviously I'll be using MAX_FILE_SIZE in my form (PHP) , but I wondered if
>anyone had any tips on checking the size and type prior to upload
>
>I don't think it can be done with JavaScript but I'm happy to be educated
>other wise (other than checking the name as a string to make sure it ends in
>.jpg or .jpeg or .png etc etc)
>
>Any ideas are welcome
>
>
>
>
>--
>Freelancers, contractors earn more with Prosperity4
>Call 0870 870 4414 or visit www.prosperity4.com
>and benefit from Inland Revenue approved expenses today.
>
>To advertise here: http://www.freelancers.net/advertising.html
>
>



Messages by Day
January 31st 2007
January 30th 2007
January 29th 2007
January 28th 2007
January 27th 2007
January 26th 2007
January 25th 2007
January 24th 2007
January 23rd 2007
January 22nd 2007
January 21st 2007
January 20th 2007
January 19th 2007
January 18th 2007
January 17th 2007
January 16th 2007
January 15th 2007
January 14th 2007
January 13th 2007
January 12th 2007
January 11th 2007
January 10th 2007
January 9th 2007
January 8th 2007
January 7th 2007
January 6th 2007
January 5th 2007
January 4th 2007
January 3rd 2007
January 2nd 2007
January 1st 2007


Messages by Month
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
March 2007
January 2007


Messages by Year
2008
2007
2006
2005
2004
2003
2002
2001
2000