Jump to content

4.1 Doc Upload, Security


tomdchi

Recommended Posts

Love the doc upload feature. I implemented something similar to one of my installs a while ago. I did some testing and and found it is possible to access files directly in the browser which of course is not good if they contain anything sensitive. I know that it appends the word "file" and a 6 digit number to the filename you are uploading but for sensitive material thats not good enough.

Cpanel users can enable hotlink protection and list the file extensions that are not allowed to be accessed directly. This does prevent direct access and redirects to a 403 error.

I have cpanel servers so that works for me. I don't know about others though.

 

Would there be a way to move the folder that the files are saved to and reference this folder in configuration.php? I have done this with templates_c and put the folder outside of the doc root.

 

Tom

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated