12 ms·
It's really hard to harden yourself against code getting interpreted by the browser (and thus allowing someone to steal cookies and impersonate other users). He
by TimothyFitz 17y ago
It's really hard to harden yourself against code getting interpreted by the browser (and thus allowing someone to steal cookies and impersonate other users). Here's a long article on exactly how complex it is (as known today):
http://tstarling.com/blog/2008/12/secure-web-uploads/ http://tstarling.com/blog/2008/12/secure-web-uploads/
Personally, I just don't trust web uploads on the same domain. Put them on a subdomain or better yet a completely separate domain, preferably served out of something set up to never execute any code whatsoever.
- jacquesm 17y agoExcellent read Timothy, thank you. I have changed some of the code because of this article. I also checked the history of all uploads to see if any of the holes mentioned had been used, and apparently there was at least one instance of somebody trying the .js route but they got hung up on the fact that the file names are changed after every download.