phppup Posted April 9, 2021 Share Posted April 9, 2021 (edited) I thought that after a fully sanitizing scrub of uploaded images, a simple display gallery would suffice. Then I was advised to change image names and rename directories for added security. Yet after all these precautions, it seems it's still insecure to exhibit user images? I recall a suggestion to have images SERVED (rather than using HTML <img> tag), but cannot find a method, starting point, or clear rationale for this. Guidance, advice, and insight to point me in the right direction, please. Edited April 9, 2021 by phppup Typos Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/ Share on other sites More sharing options...
requinix Posted April 9, 2021 Share Posted April 9, 2021 What? Scrubbing what? Change what for security? What's insecure, and what are you saying about "served" somehow not using <img> tags? Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585686 Share on other sites More sharing options...
phppup Posted April 9, 2021 Author Share Posted April 9, 2021 I want to allow users to upload images and then create a gallery. I am already checking file extension and taking other measures to ensure that the file is in fact a real image. I am changing the image name, so that even if the file is malicious, it is not easily accessible. But I'm not sure of the best way to display the images afterward. If images are uploaded to the XYZ directory, is it wise to display them from that location? Is it insecure for an image to be viewed from /blah/blah/blah/XYZ/renamedimg.jpg ? What is the safest way to approach this? Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585687 Share on other sites More sharing options...
requinix Posted April 9, 2021 Share Posted April 9, 2021 1 hour ago, phppup said: I am changing the image name, so that even if the file is malicious, it is not easily accessible. But you want people to see the image. It's supposed to be easily accessible. That said, people should not be able to dictate filenames on your server, so generating your own name for them is still a good thing.  Quote But I'm not sure of the best way to display the images afterward. If images are uploaded to the XYZ directory, is it wise to display them from that location? Is it insecure for an image to be viewed from /blah/blah/blah/XYZ/renamedimg.jpg ? What is the safest way to approach this? It doesn't really matter where the images are. Consider the avatars on this forum: mine is /uploads/monthly_2021_02/catra.thumb.png.4c523d979ea05f55c35f4277018effe8.png. The only thing that shows is the upload date (nobody cares) and original filename (arguably useful information). It's fine. Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585690 Share on other sites More sharing options...
phppup Posted April 9, 2021 Author Share Posted April 9, 2021 Am I looking for solutions when no problem exists? IÂ really thought I read something about a security risk in letting the directory that was home to images become visible. There was certainly a cautionary note to NOT let users name directories. I assumed that this (like the name of a file) was to prevent access (if a malicious file were uploaded). If none of this matters, why not allow a user to name a folder and retain image names? After all, access to the images will be readily available anyway, right? Am I not making an obvious connection here? Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585691 Share on other sites More sharing options...
requinix Posted April 9, 2021 Share Posted April 9, 2021 4 minutes ago, phppup said: Am I looking for solutions when no problem exists? Mostly. Let people upload images to a public location as long as access is supposed to be unrestricted and you do a good job verifying that the files are indeed images. If you wanted to allow all sorts of file types then this conversation would be going a different way and you'd need to consider making them private after all. Some people will say you should do it anyways. Me, not so much, because it's easy to verify that a file is an image and to ensure that it is only ever considered to be an image. The alternative is to not do that - to make them private and accessible through a script. And there are non-security benefits to that, like making it easier to count views, and full customization of the URL (with rewriting). You might as well consider whether you want to do that, but if you don't now and change your mind then you can use URL rewriting in the future to make it happen pretty easily. As for the user creating folders and specifying exact file names? No. You need to retain 100% control over exactly what each file is named and where it is placed on your server. You can incorporate the original name into the name you use, if you want, and for an image hosting thing that would probably be a good idea, but ultimately your code decides what to do. But you know, if you want to stop thinking about this, just go with the private thing. It's not wrong to do it. You have to worry about MIME types and file caching and partial responses, but those are solved problems. Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585692 Share on other sites More sharing options...
phppup Posted April 9, 2021 Author Share Posted April 9, 2021 (edited) At this point I think I'd better just stick with the areas that have problems I can overcome. Perhaps later I'll research the "private" aspect. I guess my initial thinking wasn't totally off-base. If I've VALIDATED the file fully, and changed the name anyway, then any malicious efforts should be nullified. So even if a bad intent were initiated, it should be defused. But why not let a user name a directory? Clearly locating the folder contents is not the issue? Placement? If I have a designated destination and RegEx naming requirements implemented, is there still a risk that I'm not seeing? Edited April 9, 2021 by phppup Typos Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585696 Share on other sites More sharing options...
requinix Posted April 10, 2021 Share Posted April 10, 2021 22 hours ago, phppup said: If I've VALIDATED the file fully, Validated it fully as far as you know. Quote and changed the name anyway, then any malicious efforts should be nullified. So even if a bad intent were initiated, it should be defused. Unless you consider malicious effects on the client, but dealing with those is a hassle. Quote But why not let a user name a directory? Clearly locating the folder contents is not the issue? Because the user should not have control over how things are named on your server, and because directories are irrelevant. If you want to make it look like there are directories then do that on the frontend - the actual URLs don't matter. Quote Placement? If I have a designated destination and RegEx naming requirements implemented, is there still a risk that I'm not seeing? Maybe. Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585713 Share on other sites More sharing options...
phppup Posted April 11, 2021 Author Share Posted April 11, 2021 16 hours ago, requinix said: Maybe. What is it that I (might not) be seeing? What potential problems am I inviting? Or is this just a macho induced control issue? If a sub-folder named userDirs is designated for users to create folders with names that they want, where is the harm? If a user creates folder "puppy" and instead I initiated the new folder 345 (but I equate 345 to puppy), they will still see a URL path /blah/blah/userDirs/345, right? So a hacker will not have been stalled, will they? If the folder is not allowed to contain any . $?<>/ shouldn't that protect me? Or perhaps limiting name size and allowing only alphanumerics is better? I still feel like I'm missing a valuable piece to the puzzle. Insight, please. Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585724 Share on other sites More sharing options...
requinix Posted April 12, 2021 Share Posted April 12, 2021 10 hours ago, phppup said: What is it that I (might not) be seeing? What potential problems am I inviting? My point is that it's only possible to validate and protect oneself against things that are known. Someday, someone will come up with a new attack and wasn't being protected against because it wasn't known about.  10 hours ago, phppup said: If a sub-folder named userDirs is designated for users to create folders with names that they want, where is the harm? Do you let strangers come into your home and use your toilet?  Before your next post where you shotgun another dozen questions at me, try to find the answers yourself. I only have so much time in the day. Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585746 Share on other sites More sharing options...
kicken Posted April 12, 2021 Share Posted April 12, 2021 11 hours ago, phppup said: If a sub-folder named userDirs is designated for users to create folders with names that they want, where is the harm? What if 5 different users want to make the folder "puppy"? Do you just mix all their files in that folder? What if their files are also all named "cutest.jpg"? Whoever uploads last gets the spot? That's one of the main reasons I just always generate a random name for the actual storage system of uploaded content. You don't have to deal with conflicting names. I generally just do something simple like: $ext = pathinfo($originalName, PATHINFO_EXTENSION); $newName = bin2hex(random_bytes(8)) . '.' . $ext; If I want to serve the files directly.  If I serve them via a script instead then I don't worry about the extension and just generate the random name. The original name and MIME type get stored in the db. If you want keep the original names / let users make directories then at minimum isolate each user into a folder you've defined that they cannot manipulate. For example, create a folder based on their auto-generated user ID from the database. Make sure you validate against path traversal attacks so they can't break out of that isolation.  Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585749 Share on other sites More sharing options...
MadTechie Posted April 12, 2021 Share Posted April 12, 2021 Let me start by saying phppup, your questions are very unclear, This makes it very difficult to help and will put people off offering help, You can save the images in a folder(s) or blobs in a database or save the image to a file and refer to it as via a script, Now, with "serving images" you will need to use the img tag when you display in html, you might use base64 instead of a path, e.g. URL vs BASE64 <!--URL image --> <img src='https://forums.phpfreaks.com/uploads/monthly_2020_10/logo-light.png.8ca2dc089c4e8fa3336b49fa0855692d.png' /> <!--Base64 image--> <img src="" />  If you are trying to restrict access then store the images outside public access and display via a script, <!--URL to image script --> <img src='image.php?hash=hsdgfhjsdghgsdjgj' /> //image.php $path = 'path to images outside public_html'; if($no_access){ exit(); } header('Content-type:image/png'); readfile($path.$_GET['hash'];  I hope this helps with some direction . Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585759 Share on other sites More sharing options...
phppup Posted April 14, 2021 Author Share Posted April 14, 2021 (edited) Quote What if 5 different users want to make the folder "puppy"? Do you just mix all their files in that folder? What if their files are also all named "cutest.jpg"? Whoever uploads last gets the spot? @kicken Thanks for the insight. I think/hope that I've got that figured out already, but I'll re-examine again.  Quote Make sure you validate against path traversal attacks so they can't break out of that isolation. I've been trying to cover that case too. Perhaps I'll need a new thread, but I found it quite revealing while working on "file sanitization" when I discovered that Lil Bobby Tables could access my data. I've run tests where I added ?file=../../etc/passwd To the end of a php URL, but gotten nothing unexpected. Am I just lucky? Already secure? Or a bad hacker? How can I trigger a negative result to help me implement a more positive security protocol? Edited April 14, 2021 by phppup Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585819 Share on other sites More sharing options...
gizmola Posted April 14, 2021 Share Posted April 14, 2021 There are a lot of different ways to run PHP. You can't separate a security strategy from the operating system, privilege of the web server, or privilege of the PHP script and the user it runs as. There are also bugs and gotchas that can occur, not to mention differences between operating system filesystems as to the characters allowed to be used in a filename. Requinix and Kicken both have a lot of real world experience, so they are going to provide you advice that is also opinionated. Personally there is very little benefit and a lot of potential risk to allowing users to create their own directories and files on your server, with names of their own choosing. You can always store this user input in a table, and utilize the name in various features if you really want to, but don't forget that a single bad actor could be crafting a name that may have no effect on your server, but could launch an exploit on the system of an end user.  Obvious concerns are when people try and craft paths that traverse your file system using slashes and periods.  Another concern is file names that could trick parsing like file.jpg.php or some other name that might trick your system into executing code.  A user could be using a character set that isn't supported by your file system, again causing a potential exploit that you aren't aware of. Or just allowing a name that causes your system to malfunction, because the name of the file includes case sensitivity or insensitivity, that either tricks or breaks your system entirely. Many OS's allow filenames that include spaces, tabs, and all sorts of other non-printable characters. Do you really want to open up your server, to the possibility of users creating hidden directories full of god knows what type of files, which perhaps appear to your system to be valid, but contain hidden payloads?  Quote Link to comment https://forums.phpfreaks.com/topic/312447-serving-images/#findComment-1585822 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.