Support Forums

Extra Field File Upload - Not filtering by extension

This is a discussion on Extra Field File Upload - Not filtering by extension within the Technical Support forums, part of the Technical Support Forums category; I have an extra field called "video" I have it set to allow the following file types: mpg,mpeg,wmv,flv,mov, However, if ...


Go Back   68 Classifieds Forums > Technical Support Forums > Technical Support

This topic is resolved.

If you have a similar issue that this thread does not address, open a new related support topic.

 
Thread Tools Display Modes
Old 08-27-2008, 11:49 AM   #1
Junior Member
 
Join Date: Jul 2008
Posts: 7
Rep Power: 0
nexmation is on a distinguished road
Default Extra Field File Upload - Not filtering by extension

I have an extra field called "video"
I have it set to allow the following file types: mpg,mpeg,wmv,flv,mov,

However, if a user tries to upload a jpg file, gif, etc... it is still getting uploaded to the video field.

Is there a way to make sure that the upload type checking actually works?
nexmation is offline  
Old 08-27-2008, 11:52 AM   #2
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,303
Rep Power: 125
Eric Barnes is a jewel in the rough
Default

It sounds like you may be getting a javascript error on that page.

Can you check with Firefox and see if you see any javascript warnings or errors?
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 08-27-2008, 01:47 PM   #3
Junior Member
 
Join Date: Jul 2008
Posts: 7
Rep Power: 0
nexmation is on a distinguished road
Default

Actually what I think is happening is when a user doesn't have javascript turned on in their browser is when the problem can happen.

I tried to upload a non approved file extension and was greeted with a javascript warning box telling me to use the correct file type. But I've had a bunch of users that have managed to accidentally upload jpegs where only video files should be allowed.
nexmation is offline  
Old 08-27-2008, 01:49 PM   #4
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,303
Rep Power: 125
Eric Barnes is a jewel in the rough
Default

You may want to add this as a bug in the issue tracker:
http://www.68classifieds.com/forums/project.php

That way I remember it and can add server side checking.
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 08-27-2008, 01:56 PM   #5
Junior Member
 
Join Date: Jul 2008
Posts: 7
Rep Power: 0
nexmation is on a distinguished road
Default

OK, I tested this with javascript turned off, and with no javascript, it uploaded a file with an unsupported file extension.

So it looks like the only check being done on the file uploads is with javascript, and nothing in the backend php script.

This is a HUGE security issue, because all a hacker has to do to upload a restricted file type is to turn off javascript.


It is also is a major PITA for a site administrator since a lot of regular people leave javascript turned off in their browsers.
nexmation is offline  
Old 08-27-2008, 01:57 PM   #6
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,303
Rep Power: 125
Eric Barnes is a jewel in the rough
Default

That is why I said to file a bug report.
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 08-27-2008, 02:02 PM   #7
Junior Member
 
Join Date: Jul 2008
Posts: 7
Rep Power: 0
nexmation is on a distinguished road
Default

Done:
http://www.68classifieds.com/forums/...hp?issueid=184
nexmation is offline  
Old 08-27-2008, 02:33 PM   #8
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,303
Rep Power: 125
Eric Barnes is a jewel in the rough
Default

Thank you!
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adding extra field to search.php... abkeller v3.1 Modules & Modifications 4 06-05-2007 01:15 AM
Enabled extra field and pdf file keeps "falling out" of previous listings sedonagate v3.1 Questions & Support 3 09-21-2006 09:50 PM
Maximum File Size for File Upload sporthorsebreeder v3.1 Questions & Support 2 09-02-2006 05:18 PM
Upload File Feature does not work sporthorsebreeder v3.1 Questions & Support 10 08-16-2006 11:39 AM


All times are GMT -4. The time now is 06:23 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0