Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Back to Basics: When allowing user uploads, don't allow uploads to execute code (hanselman.com)
3 points by fekberg on March 27, 2014 | hide | past | favorite | 1 comment


The author suggests not allowing uploads of files with specific extensions. That's ignoring the root cause of the problem: allowing uploads into a folder that your web server knows about. Why would you do that? Save all your uploads into some isolated directory on disk that the web server knows nothing about. What am I missing here?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: