Alex Rivera | Logout

MIME Type spoofing

Asked 2011-11-06T15:47:02.983
16

Checking for mime type in php is pretty easy but as far as I know mime can be spoofed. The attacker can upload a php script with for example jpeg mime type. One thing that comes to mind is to check the file extension of the uploaded file and make sure it matches the mime type. All of this is assuming the upload directory is browser accessible.

Question: Are there any other techniques for preventing "bad files" from getting in with mime type spoofing?

Edit
Report

1 Answer

-8

Check the extension.

<?php

$okFiles = array('jpg', 'png', 'gif');

$pathInfo = pathinfo($filename);

if(in_array($pathInfo['extension'], $okFiles)) {
    //Upload
} 
else {
    //Error
}

?>

You can also - like you said - check if the extension match the MIME type, but it's much more easy to just check the extension.

Btw why do you care about the MIME type?

answered 2011-11-06T16:12:31.023

Your Answer