Qbasicnews.com

Full Version: Apache won't let me write to the disk
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
Quote:No, unless they uploaded a php script. Again, a huge security hole - you should code your script to delete any script that doesn't have an "accepted" extension (for example, the one at QBNZ denies any file without the extensions .txt, .bas, .zip or .rar).

it's simple to do the blocking (many free scripts do this) just allow only certain types of file
So is it ok if I have a 777'ed directory, and a upload script with file type filters? Should I put the file directory out of the htdocs folder, and use aliases for it to work?
Pages: 1 2