![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Adult Content Provider
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
|
Is this safe?
I am running a community driven website where I need to be able to have users submit html files through a contact form with file upload which forwards the file and message to my email. Is this safe or does it pose some kind of security threat if there is a rogue user who decides to upload an html file with malicious code?
I have security apps on my computer I am more concerned if it can hurt my server in some way. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Adult Content Provider
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
|
I will block everything but *.html files but I guess that can be exploited anyway.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Too lazy to set a custom title
Join Date: Jan 2002
Location: Holland
Posts: 9,870
|
why do you need the submission of a complete html file? Easy to install exploits that way.
__________________
Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Too lazy to set a custom title
Industry Role:
Join Date: Mar 2003
Location: Homeless
Posts: 62,911
|
.htm and .html just incase
__________________
PornGuy skype me pornguy_epic AmateurDough The Hottes Shemales online! TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Adult Content Provider
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
|
I guess I could just have them submit the code in a text field but we are dealing with complete newbies so I fear they will not know how to extract the code from the html file as stupid as it may sounds.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Join Date: Mar 2008
Posts: 8,960
|
Easy for spammers.
__________________
| _TeenageDecadence - Young Board Naked Teens. |
| ____ NonNudeGirls - Female Puberty Photos. ____ | | _ HerSelfPics - The ORIGINAL exGF SelfPic site. __ | \.______ xPosing - Wife Photosharing site. _______./ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Mar 2009
Location: NP-hard
Posts: 287
|
Take care - if your server is configured in that way, <?php ?> tags will be parsed with HTML files (depends on how you use the files after upload). Strip all code, be it PHP, ASP, etc. And strip ALL javascript. ALL of it.
That should be safe - I would use one more precaution though: don't allow anything referencing outer domains (eg. hotlinking an image for example from domain2.com, where the HTML file is uploaded to domain1.com) - this is a prime candidate for cookie stuffing. Just my ![]() take care !!! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
Adult Content Provider
Industry Role:
Join Date: May 2005
Location: Europe
Posts: 18,243
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: Mar 2009
Location: NP-hard
Posts: 287
|
no prob mate, hit me up if you've got some scripting security issues, I have a lot of experience with this
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Join Date: Mar 2009
Location: NP-hard
Posts: 287
|
just one more thought - why don't you get your users to edit HTML online, with an editor? (FCKEditor for example, but there are a lot out there) It would be WAY more safe...
|
![]() |
![]() ![]() ![]() ![]() ![]() |