Re: Critical phpwiki c99shell exploit

看板Bugtraq作者時間19年前 (2007/04/17 03:55), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/4 (看更多)
Hello, Gadi Evron wrote: > This is a good best practice, but it doesn't hold water long > range. Further, where do you disallow these extensions? In the > application? > Mostly what the bad guys would do is upload, say.. .jpg, and then rename > it. This is what I do in Apache to directories used to store user uploaded files: <Directory "/var/www/html/application/uploaded"> php_admin_flag engine off </Directory> -- Taneli Lepp | Crasman Co Ltd <taneli@crasman.fi> | <http://www.crasman.fi/>
文章代碼(AID): #168zJ200 (Bugtraq)
文章代碼(AID): #168zJ200 (Bugtraq)