BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Critical phpwiki c99shell exploit Apr 16 2007 10:29AM
Taneli Leppä (taneli crasman fi)
Hello,

Gadi Evron wrote:
> This is a good best practice, but it doesn't hold water long
> range. Further, where do you disallow these extensions? In the
> application?
> Mostly what the bad guys would do is upload, say.. .jpg, and then rename
> it.

This is what I do in Apache to directories used t...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus