Ways to stop people from uploading GIFs with injections in them?

后端 未结 7 674
无人共我
无人共我 2021-02-01 06:36

I have a PHP website where people can fill out help-tickets. It allows them to upload screenshots for their ticket. I allow gif, psd, bmp, jpg, png, tif to be uploaded. Upon

7条回答
  •  夕颜
    夕颜 (楼主)
    2021-02-01 07:08

    I dont know much about image formats, but recreating the images and then storing the result, I feel has a good chance of eliminating unnecessary tricky stuff. Especially if you strip all the meta data like comments and all the other types of optional embedded fields that some image formats support.

提交回复
热议问题