PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Wed Nov 20, 2019 6:26 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Sun Apr 21, 2013 4:18 am 
Offline
Forum Newbie

Joined: Sun Apr 21, 2013 3:26 am
Posts: 1
if i ignore directory execute permission, can i upload every file even .php,.exe,... ???
is there any risk whit is???


Top
 Profile  
 
PostPosted: Sun Apr 21, 2013 5:54 am 
Offline
Spammer :|
User avatar

Joined: Wed Oct 15, 2008 2:35 am
Posts: 6617
Location: WA, USA
The "execute" permission for directories is not actually for executing things. It's a misnomer.

Whatever the permission, someone can upload whatever files they want as long as your script allows it. If you don't want people to upload bad files then make sure they're only uploading good files (whatever those may be, like just images or just .doc files or whatever). What happens to uploaded files depends on your server configuration but in general yes: if they manage to upload a .php file then it can probably be executed just like any other PHP script you have.


Top
 Profile  
 
PostPosted: Sun Apr 21, 2013 11:30 am 
Offline
DevNet Master
User avatar

Joined: Sun Feb 15, 2009 12:08 pm
Posts: 2794
Location: .za
an interesting read OP, will shed some light on your thoughts about what can be done if no checking / restriction is in place for file uploads

_________________
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.” - Mosher’s Law of Software Engineering


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group