Jump to content

getimagesize() Question


N-Bomb(Nerd)

Recommended Posts

First of all, would using the function getimagesize() be a sure fire way to see if an uploaded file is actually an image? Besides the obvious 'mime' type, what else could I use to be sure it's actually an image?

 

Also, is there actually a way someone could "embed" malicious code inside of an image and have it execute on my server?

Link to comment
Share on other sites

mime is plenty enough... plus someone injecting code into an image file, is not unreal, but chances of it actually being run are almost none... I mean if you coding runs the image file through bash then your code is horrible. 

Link to comment
Share on other sites

mime is plenty enough... plus someone injecting code into an image file, is not unreal, but chances of it actually being run are almost none... I mean if you coding runs the image file through bash then your code is horrible.

 

Well, I just like being sure as I have some stuff on my server that really isn't meant for anybody else to see..

 

I don't want to get hacked and have all my shit leaked just because of an image uploader on one of my websites.

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.