【问题标题】:PHP Uploading files - image only checkingPHP上传文件 - 仅检查图像
【发布时间】:2012-03-08 00:30:44
【问题描述】:

我已经启动了一个简单的 PHP 上传脚本。我不是最适合PHP的。只是在寻找一些建议。

我想将我的脚本限制为仅 .JPG、.JPEG、.GIF 和 .PNG

这可能吗?

<?php
/*
    Temp Uploader
*/

    # vars
    $mx=rand();
    $advid=$_REQUEST["advid"];
    $hash=md5(rand);

    # create our temp dir
    mkdir("./uploads/tempads/".$advid."/".$mx."/".$hash."/", 0777, true);

    # upload dir
    $uploaddir = './uploads/tempads/'.$advid.'/'.$mx.'/'.$hash.'/';
    $file = $uploaddir . basename($_FILES['file']['name']);

    // I was thinking of a large IF STATEMENT HERE ..

    # upload the file
    if (move_uploaded_file($_FILES['file']['tmp_name'], $file)) {
      $result = 1;
    } else {
      $result = 0;
    }

    sleep(10);
    echo $result;

?>

【问题讨论】:

标签: php image file-upload


【解决方案1】:

是的,很容易。但首先,你需要一些额外的东西:

// never assume the upload succeeded
if ($_FILES['file']['error'] !== UPLOAD_ERR_OK) {
   die("Upload failed with error code " . $_FILES['file']['error']);
}

$info = getimagesize($_FILES['file']['tmp_name']);
if ($info === FALSE) {
   die("Unable to determine image type of uploaded file");
}

if (($info[2] !== IMAGETYPE_GIF) && ($info[2] !== IMAGETYPE_JPEG) && ($info[2] !== IMAGETYPE_PNG)) {
   die("Not a gif/jpeg/png");
}

相关文档:file upload errors、getimagesize 和 image constants。

【讨论】:

  • 打败我 - 这种方法确保文件是图像,而不仅仅是命名为图像。
  • 唯一需要注意的是 GD 不是 PHP 的 oob 并且可能很挑剔。 finfo_file 在 PHP 5.3.0 之后是标准的,也会做基于内容的检查。
  • 如何查看文件分辨率? IE Size if width and height??
  • 一个gif就是一个gif。它们都在文件开头共享相同的幻数。
  • “不要使用 getimagesize() 来检查给定文件是否为有效图像。请改用专用解决方案,例如 Fileinfo 扩展。”见php.net/manual/en/function.getimagesize.php
【解决方案2】:

文件路径不一定是检查图像是否真的是图像的最佳方法。我可以获取一个恶意 javascript 文件,将其重命名为具有 .jpg 扩展名,然后上传。现在,当您尝试在您的网站上显示它时,我可能刚刚入侵了您的网站。

这是一个验证它是否真的是图像的函数:

<?php
  function isImage($img){
      return (bool)getimagesize($img);
  }
?>

【讨论】:

  • Do not use getimagesize() to check that a given file is a valid image. Use a purpose-built solution such as the Fileinfo extension instead. - Docs
【解决方案3】:

试试这个:

<?php

function isimage(){
$type=$_FILES['my-image']['type'];     

$extensions=array('image/jpg','image/jpe','image/jpeg','image/jfif','image/png','image/bmp','image/dib','image/gif');
    if(in_array($type, $extensions)){
        return true;
    }
    else
    {
        return false;
    }
}

    if(isimage()){
        //do codes..
    }

?>

【讨论】:

  • 您的帖子被标记为低质量,因为它都是代码。试着解释你做了什么。
【解决方案4】:

【讨论】:

    【解决方案5】:
    if (substr($_FILES["fieldName"]["name"], strlen($_FILES["fieldName"]["name"])-4) == ".jpg")
    {
        if(move_uploaded_file($_FILES["fieldName"]["tmp_name"],$path."/".$_FILES['fieldName']['name']))
        {
            echo "image sucessfully uploaded!";
        }
    }
    

    同样,您也可以检查其他图像格式。

    【讨论】:

    • 您假设远程用户没有恶意并且不会只是将nastyvirus.exe 重命名为cutekittens.jpg。
    猜你喜欢
    • 2017-06-11
    • 2013-07-03
    • 1970-01-01
    • 1970-01-01
    • 2013-01-25
    • 1970-01-01
    • 2016-01-25
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多