> Is it possible that a user or browser could send false MIME
> types?

Yes, of course. You could say whatever MIME type you want if you write the
HTTP request yourself.

> That's why I check the extension, because if someone somehow
> spoofs a MIME type and uploads an exe to my server, I don't
> want it to get written to the file system.

That's probably a good idea. In addition, you shouldn't allow people to
upload files to directories that allow files to be executed.

Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
phone: 202-797-5496
fax: 202-797-5444
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings] [Donations and Support]

Reply via email to