You're right for upload you need a good one. Upload scripts are routinely hacked. The bad guy uploads their own php script and your site is fucked, especially if you use Plesk and therefore suexec.
We can help you out. If the script is publicly accessible so visitors can upload, we can also serve as a second pair of eyes to spot the holes in one done by someone else.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
|