[UPHPU] Safe File Upload

Justin Giboney giboney at giboneydesigns.com
Tue Oct 16 12:40:52 MDT 2007


John David Anderson wrote:

> What googled up articles have you already tried and decided not to  
> use?  ;)

I have tried

http://www.tizag.com/phpT/fileupload.php
- but it says "*Note:* This script is for education purposes only. We do 
not recommend placing this on a web page viewable to the public."

http://www.php.net/manual/en/features.file-upload.php
- but this one doesn't say anything about being safe

http://www.zymic.com/tutorials/php/creating-a-file-upload-form-with-php/
- this one says it is safe, but it only seems to talk about checking the 
file extension and size

I don't really know what it needs to do in order to be "safe," but I 
don't want to expose myself or my clients to malware

Thank you,

Justin Giboney



More information about the UPHPU mailing list