02.12.2012 Views

File in the hole!

File in the hole!

File in the hole!

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

� We don’t need bypass for file upload<br />

� Write access <strong>in</strong> Upload directory is needed<br />

� Webserver needs to be configured not FS<br />

� Not hav<strong>in</strong>g execute permission does not help!<br />

� Write permission can be prohibited outside<br />

� What about Temp/Real Time files/folders?<br />

� Still bad if you can upload arbitrary files<br />

� It is good to have this to reduce <strong>the</strong> risk

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!