Developer resources

Handling file uploads safely

If your item accepts files, it accepts whatever an attacker chooses to send. This is the highest-risk surface in most shipped software and it is usually the least considered.

Never trust the extension

The filename comes from the client and can say anything. Check what the file actually is, by inspecting its contents, and treat that as the truth.

Never trust the mime type either

The browser supplies it and it is equally forgeable. Both together are a hint, not a check.

Rename everything you store

Generate your own name, with your own extension derived from what you verified. This removes path traversal, double extensions and every trick that depends on controlling the filename.

Store outside the web root, or stop execution

An uploaded file the web server will execute is the whole game lost. Either keep uploads where the server cannot serve them and stream through your own code, or ensure that directory cannot execute anything.

Re-encode images

Processing an uploaded image and writing a new file from the result discards anything hidden inside the original. This is cheap and it removes an entire class of attack.

Limit size, count and rate

Not just per file. A hundred allowed uploads in a minute fills a disk, and a full disk takes the site down as effectively as anything malicious would.

Related: security mistakes that get items rejected.

Turn your code into income.

Join the authors selling templates, scripts and plugins to developers worldwide. Keep up to 85% of every sale.

Start selling →