Php photo gallery TWG | JFUploader | TWG Flash upload | WFU | Forum
https://www.tinywebgallery.com/forum/

TFU security
https://www.tinywebgallery.com/forum/viewtopic.php?f=12&t=1800
Page 1 of 1

Author:  itsa [ 11. Jan 2009, 19:11 ]
Post subject:  TFU security

I have read the how-to#13 about this, but I have an extra question.

I would prefer not to use the 'auth' for TFU. How safe is it to only use TFU without authentification? Do I put my website at risk? :roll:
Does hiding the remote view, blocking the folders and filenames options changes anything about how secure TFU is?

Thank you,

itsa

Author:  TinyWebGallery [ 11. Jan 2009, 23:22 ]
Post subject: 

TFU itself is secure. It's about who can use the flash.

If you allow everyone to upload images (public uploader) only then there is no risk. But if you allow other extensions you should be sure only to use extensions that cannot be executed somehow on your server.

Howto 13 is important if you have an authentification and you don't want that everyone can call the flash directly and bypass your login.

- Michael

Author:  itsa [ 11. Jan 2009, 23:47 ]
Post subject: 

OK, that's good! I am glad it is secure. I will have to edit the settings ref the allowed extensions.

itsa

Page 1 of 1 All times are UTC + 1 hour [ DST ]
Powered by phpBB® Forum Software © phpBB Group
http://www.phpbb.com/