TrophyCustomer's Canvas is honored with a 2020 InterTech Technology Award! Learn more 
Welcome Guest! You need to login or register to make posts.



Go to last post Go to first unread
#1 Posted : Monday, February 28, 2005 11:39:00 PM(UTC)

Rank: Member

Groups: Member
Joined: 9/20/2004(UTC)
Posts: 3


We're using version 3.0. Is it true that the file signature verification (SignatureFilter = "known") and file name filter (FileMask = "*.JPG;*.JPEG;*.GIF;*.PNG) are separate filters? That is, the file signature test is done first, and then, separately, the file mask test is done?

We've seen a case where a BMP file which was renamed to have a .JPG suffix was uploadable, even through one would not expect it to be. Is it possible to add a test where the file name extension is used to guide the signature test, to make sure the file is what it claims to be?


Users browsing this topic
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.