There is a part of my site that allows users to upload profile photos. I worry about people downloading malicious code. I plan to limit the file types .jpg / .png / .gif / .jpeg
I worry that this will not be enough. I am going to resize images on the server. Will the process of resizing photos be sufficient to ensure that the image is actually an image of non-malicious files?
I will use the following to resize photos. I will not store the originals on the server, and the file names will be changed.
imagecopyresampled($thumb, $source, 0, 0, 0, 0, $newwidth, $newheight, $width, $height); imagejpeg($thumb, $fullpath, 90);
source share