rubyonrailsin

A Ruby and Rails talk

Monday, March 29, 2010


[Rails] Re: Can the .read method execute any files?

by rubyonrailsin 0 comments

Tag


Share this post:
Design Float
StumbleUpon
Reddit

If you are planning on just uploading the file and you don't want to
upload executable files you should check for that before allowing the
upload.

On 29 mar, 09:17, GoodGets <goodg...@gmail.com> wrote:
> I need to read (and parse) a user uploaded file.  I check it's MIME
> types, as well to see if includes proper headers by reading the file,
> but I was wondering can something like params[:uploaded_file].read
> trigger any EXEs or ruby/php/etc files?  Or, is "read" good to go?

--
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group.
To post to this group, send email to rubyonrails-talk@googlegroups.com.
To unsubscribe from this group, send email to rubyonrails-talk+unsubscribe@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/rubyonrails-talk?hl=en.

No comments:

Post a Comment

Subscribe feeds via e-mail

Blog Archive