View Single Post
Old 04-11-2007, 05:19 AM  
StarkReality
Confirmed User
 
StarkReality's Avatar
 
Join Date: May 2004
Location: 4 8 15 16 23 42
Posts: 4,444
Quote:
Originally Posted by Kaylum View Post
also, don't sweat any concern with viruses for images.. the files aren't excecuted (ran), and you can modify or have someone else modify the script to check for image type/file size.
Sorry, but that's wrong. Recently a LFI (Local File Inclusion) exploit showed up, it's pretty popular right now that let's you embed php code in jpg images...and many scripts are vulnerable to it, incuding well known forum and blogging scripts. They show up as normal pictures and bypass any checks by the script.
StarkReality is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook