Link to home
Start Free TrialLog in
Avatar of Shopies
Shopies

asked on

secured file uploading

Hi,
I have just made a scripts which allows my website members to upload thier images, avatars ...etc. This script isn't secure since anyone can upload anything via it. This script doesn't check wither the file upload is an image or not. Simply anyone can upload a SHELL file to hack my website.

Is there anyway to secure this script? Is it a good idea to keep files being upload on the same server of my website?

Best Regards,
Hakeem
Avatar of Scott Bennett
Scott Bennett
Flag of United States of America image

What language are you using for your server side scripting? Every mainstreem language should have the capability or retricting which files can be uploaded based on the files MIME type. tell me what language you are using and I can give you an example.
Avatar of Shopies
Shopies

ASKER

I'm using PHP
Thanks for posting
ASKER CERTIFIED SOLUTION
Avatar of Scott Bennett
Scott Bennett
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial