Ask the high person to detect the website security problems as the question, ask the high person to check the website security site for hmu027173.chinaw3.com problems, the background is always uploaded files, resulting in excessive resources on the server, as a result, almost every directory of files uploaded when the website is closed can be uploaded, which is depressing. Thank you for your help. solution -------------------- set various permissions ~ You do not need to add the write permission to all directories. ------ Solve the problem of high-profile website security
For example, ask someone to check the website security.
The site is http://hmu027173.chinaw3.com/
Problem: files are always uploaded in the background, causing excessive resources on the server and website shutdown.
Almost every Directory of the uploaded file can be uploaded, which is depressing.
Thank you for your help.
------ Solution --------------------
Set various permissions ~
You do not need to add the write permission to all directories.
------ Solution --------------------
1. according To 1L, unless the write permission and running permission of the upload Directory
2. check all the code involved in the upload and impose restrictions on the path of the upload directory.
------ Solution --------------------
Directory permission,
Determine the type of the uploaded file page.