FRIHOST FORUMS SEARCH FAQ TOS BLOGS COMPETITIONS
You are invited to Log in or Register a free Frihost Account!


Uploading music script security risks?





flatliner
Hi everyone

I am currently working on a very large multimedia web base project. Which includes the uploading of a lot of content some of which, would be m3p and wav files etc I.E music files. I was just wondering are there any added security risk with music files like there are with images??

I know you have your standard checks, like is the file executable and that, but in terms of certain extension or that. Any feedback on this would be great thanks.

Kind Regards
Ciaran Mc Cann
rvec
make sure it is one of the files from a list of extensions, give it a maximum and minimum size (>0), make sure $_FILES['error'] is 'UPLOAD_ERR_OK' and $_FILES['tmp_name'] is not 'none'.
Before publishing files also make sure the uploader has copyright or publishing permission.

That should cover about everything I guess.
AftershockVibe
Failing a team of moderators for uploaded files (which is the best method), you could do what some of the video upload sites do perhaps - automatically block high volume files.

While it won't stop little Jimmy sharing a bootleg mp3 with 3 of his mates, it will stop your bandwidth going down the plug after it's posted to a forum for the world to download.

Or did you mean in relation to malware in a similar vein to the implementation flaw in the JPEG libraries that allowed execution of code from a cleverly crafted image?
flatliner
Thanks for the feedback guys.
Well all the music will be screened and it will all hopefully be self produce works. The music will be stream-able from the site. I don't want the music download-able site, so no fear of large bandwidth from downloading.

AftershockVibe wrote:
Or did you mean in relation to malware in a similar vein to the implementation flaw in the JPEG libraries that allowed execution of code from a cleverly crafted image?

yea that really then anything else.
flatliner
Any one else have anymore information to add?
Thanks
Related topics
*OFFICIAL* Which Browser do you use?
Windows Tips&tricks!
Account suspended (Fourthbean)
How To : Secure Your PHP Website
Sony CD EULA
Why is it that everything I do does not work!
MySQL problem (as usual)
Music Support
minangnesse music
Music Script
Multiple Servers
Directory lister
What do you consider to be the most important security issue
asp.net email form
Reply to topic    Frihost Forum Index -> Scripting -> Php and MySQL

FRIHOST HOME | FAQ | TOS | ABOUT US | CONTACT US | SITE MAP
© 2005-2011 Frihost, forums powered by phpBB.