Please help. Hacker alert. They are executing PHP with images

Discussion in 'PHP' started by x0x, Aug 17, 2008.

  1. Vooler

    Vooler Well-Known Member

    Messages:
    1,146
    Likes Received:
    64
    Best Answers:
    4
    Trophy Points:
    150
    #21
    he is absolutely right, but getimagesize does not make sure either image has extra byes at the end of stream or not, for that reason I prefer imagecreatefromtring.

    Major concern: In conjunction later use imagejpeg, imagepng but not move_uploaded_file.

    But, ofcourse getimageisze relies on header only, and not loads not entire file in memory, less cpu usage.

    regards
     
    Vooler, Aug 18, 2008 IP
  2. Shoro

    Shoro Peon

    Messages:
    143
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #22
    Spamming md5 doesn't give you more security. It actually gives you less security because you're hashing a hash that's always going to be exactly 32 characters and comprised of only numbers and the letters a to f. It's better to just use crypt with a variable salt.
     
    Shoro, Aug 18, 2008 IP