Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
randallsquared
on March 24, 2008
|
parent
|
context
|
favorite
| on:
Secure File Upload in PHP Applications
However, if it's important to disallow random access to the uploaded file, you really need to put access controls on it, and store it outside of the HTTP root. Obscuring the filename isn't enough.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: