PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > alt.apache.configuration > Secure a web-accessible upload directory
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
alt.apache.configuration Apache web server configuration issues.

Secure a web-accessible upload directory

Réponse
 
LinkBack Outils de la discussion
Vieux 29/09/2006, 02h49   #1
7elephants
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Secure a web-accessible upload directory

Hi,

I have a site running Linux/Apache/PHP that users can uploads photos to
a directory within the webroot. The only way that I have been able to
get the upload to work is if I chmod the upload directory to 777. The
site is running at a shared hosting provider so I don't have access as
to who apache and/or PHP is running under, but I assume nobody. How
can I get the upload to work while not exposing the directory as a huge
security hole?

Thanks in advance.

  Réponse avec citation
Vieux 02/10/2006, 14h12   #2
Newsgroup Poster
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Secure a web-accessible upload directory

quite simply you can't as ur on a shared hosting platform.

there are scripts that will only allow certain filetypes uploaded ie: .gif .jpg .doc .pdf .txt


"7elephants" <andrew@andrewsteiger.com> wrote in message news:1159494594.253919.190750@k70g2000cwa.googlegr oups.com...
> Hi,
>
> I have a site running Linux/Apache/PHP that users can uploads photos to
> a directory within the webroot. The only way that I have been able to
> get the upload to work is if I chmod the upload directory to 777. The
> site is running at a shared hosting provider so I don't have access as
> to who apache and/or PHP is running under, but I assume nobody. How
> can I get the upload to work while not exposing the directory as a huge
> security hole?
>
> Thanks in advance.
>



  Réponse avec citation
Vieux 02/10/2006, 15h44   #3
Ottavio Caruso
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Secure a web-accessible upload directory

Newsgroup Poster wrote:
> quite simply you can't as ur on a shared hosting platform.


That depends. If you can run cgi's and the server runs suexec, you
could run your php scripts as cgi. Then you wouldn't need to chmod the
directory 777; 700 would do. Also, you should put the upload directory
outside the web tree, which, again, your web provider may not offer
you.

PHP5 should have some object oriented libraries that may offer a
workaround to this problem. With php4 on a shared hosting, it's nealy
impossible.

You are better off asking a php newsgroup.

Ottavio

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 19h31.


Édité par : vBulletin® version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,07719 seconds with 11 queries