Login Register


[*FIXED*] Issue with in_array() [strange] filter_list
Author
Message
RE: Issue with in_array() [strange] #31
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row
Calling me stupid won't mind me it only shows your immaturity -<3

[Image: 120x240.gif]

Reply

RE: Issue with in_array() [strange] #32
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row
Calling me stupid won't mind me it only shows your immaturity -<3

[Image: 120x240.gif]

Reply

RE: Issue with in_array() [strange] #33
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row
Calling me stupid won't mind me it only shows your immaturity -<3

[Image: 120x240.gif]

Reply

RE: Issue with in_array() [strange] #34
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row
Calling me stupid won't mind me it only shows your immaturity -<3

[Image: 120x240.gif]

Reply

RE: Issue with in_array() [strange] #35
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row
Calling me stupid won't mind me it only shows your immaturity -<3

[Image: 120x240.gif]

Reply

RE: Issue with in_array() [strange] #36
(10-29-2013, 12:48 AM)hellomen Wrote:
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row

oh wait, my bad Tongue sorry, when talking about file uploads I automatically assume you are saving them Smile

hmm, I'm sure we could find some vulns there anyway Tongue
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Issue with in_array() [strange] #37
(10-29-2013, 12:48 AM)hellomen Wrote:
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row

oh wait, my bad Tongue sorry, when talking about file uploads I automatically assume you are saving them Smile

hmm, I'm sure we could find some vulns there anyway Tongue
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Issue with in_array() [strange] #38
(10-29-2013, 12:48 AM)hellomen Wrote:
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row

oh wait, my bad Tongue sorry, when talking about file uploads I automatically assume you are saving them Smile

hmm, I'm sure we could find some vulns there anyway Tongue
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Issue with in_array() [strange] #39
(10-29-2013, 12:48 AM)hellomen Wrote:
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row

oh wait, my bad Tongue sorry, when talking about file uploads I automatically assume you are saving them Smile

hmm, I'm sure we could find some vulns there anyway Tongue
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply

RE: Issue with in_array() [strange] #40
(10-29-2013, 12:48 AM)hellomen Wrote:
(10-29-2013, 12:34 AM)1llusion Wrote:
(10-29-2013, 12:26 AM)hellomen Wrote: it is accepting: image/jpg image/jpeg and image/gif which are mime types
all other types are yet blocked out...

Unless you changed the way you check for this stuff, it is still vulnerable.

Best explanation is here (also with good pointers): http://security.stackexchange.com/questi...pload-form
be aware it doesn't save the files on the web server itselves
it saves it in a database those vulnerabilities are for webserver savement

the BLOB on a database also only allows images so whenever the user tries to bypass part one the database says hehe this is not worthly for the blob row

oh wait, my bad Tongue sorry, when talking about file uploads I automatically assume you are saving them Smile

hmm, I'm sure we could find some vulns there anyway Tongue
Staff will never ever ask you for your personal information.
We know everything about you anyway.

Reply







Users browsing this thread: 1 Guest(s)