File upload

Wratox1

Member
Reaction score
22
im making a site where you can watch flashfiles(.swf), and i made an upload page where you can upload .swf-files and i have this code to upload the file:

PHP:
<?php
// Configuration - Your Options
      $allowed_filetypes = array('.swf'); // These will be the types of file that will pass the validation.
      $max_filesize = 5242880; // Maximum filesize in BYTES (currently 5MB).
      $upload_path = './flash/'; // The place the files will be uploaded to (currently a 'files' directory).
	  $count = count(glob("$upload_path/*.*"));
	
	$filename = $_FILES['file']['name']; // Get the name of the file (including file extension).
	$ext = substr($filename, strpos($filename,'.'), strlen($filename)-1); // Get the extension from the filename.
 
	// Check if the filetype is allowed, if not DIE and inform the user.
	if(!in_array($ext,$allowed_filetypes))
      die('The file you attempted to upload is not allowed.');
 
	// Now check the filesize, if it is too large then DIE and inform the user.
	if(filesize($_FILES['file']['tmp_name']) > $max_filesize)
      die('The file you attempted to upload is too large.');
 
	// Check if we can upload to the specified path, if not DIE and inform the user.
	if(!is_writable($upload_path))
      die('You cannot upload to the specified directory, please CHMOD it to 777.');
	
	$count += 1;
	$name = "$count";
	
	if (move_uploaded_file($_FILES['file']['tmp_name'], $upload_path.$name.'.swf'))
	{
		die('File is valid, and was successfully uploaded.');
	}
	else
	{
		die('Possible file upload attack! <br> ' . $_FILES['file']['name'] . '<br>' . filesize($_FILES['file']['tmp_name']));
	}
 

?>

can i make it safer against upload-attacks?

//Wratox
 
What sort of upload attacks do you want protecting against? You are already limiting the files to .swf files, which means they can't attach .exes or anything.
 
i want to protect against most upload attacks, one i had in mind was if someone uploaded a file like this: "filename.php.swf", am i still protected against that?
 
Yes, as that will still work as a .swf file, unless they somehow managed to change the file extension. If you want to be 100% sure, you can check the file extension before displaying it on the page, which means it will definately be a .swf when you actually use it.
 
I know the extension might be wrong, but the mine type is usually right. $_FILES['myFileInput']['mime'] == 'application/x-shockwave-flash'
 
maybe also limit special characters and allow only one . (or auto re-name/remove extra stuff)
 
General chit-chat
Help Users
  • No one is chatting at the moment.
  • V-SNES V-SNES:
    Happy Friday!
    +1
  • The Helper The Helper:
    News portal has been retired. Main page of site goes to Headline News forum now
  • The Helper The Helper:
    I am working on getting access to the old news portal under a different URL for those that would rather use that for news before we get a different news view.
  • Ghan Ghan:
    Easily done
    +1
  • The Helper The Helper:
    https://www.thehelper.net/pages/news/ is a link to the old news portal - i will integrate it into the interface somewhere when i figure it out
  • Ghan Ghan:
    Need to try something
  • Ghan Ghan:
    Hopefully this won't cause problems.
  • Ghan Ghan:
    Hmm
  • Ghan Ghan:
    I have converted the Headline News forum to an Article type forum. It will now show the top 20 threads with more detail of each thread.
  • Ghan Ghan:
    See how we like that.
  • The Helper The Helper:
    I do not see a way to go past the 1st page of posts on the forum though
  • The Helper The Helper:
    It is OK though for the main page to open up on the forum in the view it was before. As long as the portal has its own URL so it can be viewed that way I do want to try it as a regular forum view for a while
  • Ghan Ghan:
    Yeah I'm not sure what the deal is with the pagination.
  • Ghan Ghan:
    It SHOULD be there so I think it might just be an artifact of having an older style.
  • Ghan Ghan:
    I switched it to a "Standard" article forum. This will show the thread list like normal, but the threads themselves will have the first post set up above the rest of the "comments"
  • The Helper The Helper:
    I don't really get that article forum but I think it is because I have never really seen it used on a multi post thread
  • Ghan Ghan:
    RpNation makes more use of it right now as an example: https://www.rpnation.com/news/
  • The Helper The Helper:
  • The Helper The Helper:
    What do you think Tom?
  • tom_mai78101 tom_mai78101:
    I will have to get used to this.
  • tom_mai78101 tom_mai78101:
    The latest news feed looks good

      The Helper Discord

      Members online

      No members online now.

      Affiliates

      Hive Workshop NUON Dome World Editor Tutorials

      Network Sponsors

      Apex Steel Pipe - Buys and sells Steel Pipe.
      Top