Verify that the suffix of the uploaded file is not a good method, because someone else uses the suffix of the Trojan to change it to .jpg. Is there a more secure way to verify the correct type of uploaded files? ------ Solution ------------------ the worst way to copy and paste FILES is to detect the type of the uploaded file through $ _ FILES [...] [type], because it can be forged simply by modifying the file extension. Verify the type of the uploaded file.
By verifying the suffix, it is not a good method, because someone else uses the suffix of the Trojan to change it to .jpg. Examples of intrusion
Is there a safer way to verify the correct type of uploaded files?
------ Solution --------------------
Copy and paste
The worst way is to use $ _ FILES [...] ['type'] to detect the type of the uploaded file, because it can be forged simply by modifying the file extension.
Another method of relative security is to determine the type of the uploaded file by using the content of the first two bytes. The example code is as follows:
$ Handle = fopen ($ _ FILES [...] ['tmp _ name'], 'RB ');
$ Content = fread ($ handle, 2 );
Fclose ($ handle );
$ Info = unpack ('c2chars', $ content );
If (emptyempty ($ info ['chars1']) | emptyempty ($ info ['chars2']) {
Exit ('error! ');
}
If ($ info ['chars1'] <0 ){
$ Info ['chars1'] + = 256;
}
If ($ info ['chars2'] <0 ){
$ Info ['chars2'] + = 256;
}
$ Code = $ info ['chars1']. $ info ['chars2'];
The pack & unpack functions in PHP are dazzling. if you are interested, see Handling binary data in PHP with pack () and unpack ()
Note: most of the relevant online search programs do not perform 256 of the relevant operations. this is the TDD result I committed myself through the test data. it is not sure whether it is correct. the readers will consider it for themselves.
You can determine the $ code variable through the switch to correspond to the file type. the common image type results are roughly as follows:
GIF: 7173
. JPG: 255216
. PNG: 13780
Of course, you can also determine other file types, and you will know the value size by doing experiments on your own. However, this method is not necessarily safe, because the content of the first two bytes can also be forged, so it is best to restrict the file extension to prevent accidental parsing, for example, you create a project named foobar. the content of the php file is as follows:
GIF89
When you use the first two bytes to detect the file type, you will get the GIF: 7173 result. even if you use the file command in shell to detect the file type, you will mistakenly think of the GIF image:
# File foobar. php
Foobar. php: GIF image data 16188x26736
Because the extension is. php, the file will be parsed by the php engine. as a result, the hacker will be given a web shell, and security will not be discussed. So it is very important to limit the file extension. remember! As for how to discover this kind of disguise, the simplest method is to use shell commands to filter it again:
# Strings foobar. php | grep-I"
If you want to completely eliminate such risks, you can use tools such as gd, imagemagick, and graphicsmagick to edit the images you have uploaded before saving them. this will erase possible embedded code. If you want to be more secure, you should also separate the image server and parse static files without installing php.
Supplement: If you only judge an image, there is a simpler method, namely getimagesize. Although this method is used to obtain the image size from the name, the result contains the image type, in addition, although this method is summarized in the GD section in the document, it is available even if GD is not installed. However, you should pay attention to security issues as before.