code injection - Can a php shell be injected into an image? How would this work? -


i remember seeing exploit image uploading function, consisted of hiding malicious php code inside tiff image.

i'm making own image uploading script, , assume i'll have protect myself possibility. except, have no idea how work. know how php shell hidden inside image execute itself? need loaded in way?

thanks.

re encoding image not stop uploading shell. sure way prevent re-encode , scan image presence of php tags.

for example of php png shell survive re-encoding


Comments

Popular posts from this blog

linux - Mailx and Gmail nss config dir -

c# - Is it possible to remove an existing registration from Autofac container builder? -

php - Mysql PK and FK char(36) vs int(10) -