My website would like users to upload their photos ... but how can I protect our server from harm? Allowing JPG only should avoid problems with the virus, but what if someone selects a 10Gb file - will it slow down the whole site?
We use classic ASP and IIS6 (sorry, but be that as it may, this cannot change!). We used to use Persits DLLs to handle downloads. However, it would be helpful to other people if we extend this discussion to other languages / technologies.
ASPs cannot determine the size of the file until it completes the download, so this is a pain. Or can I check the length of the content in the HTTP header before starting the transfer?
Q1. Are there other ways someone can abuse the download tool?
Q2. How can I limit the danger to site security and server security?
Thanks.
source
share