DwZone Forum DwZone Forum
Welcome to the DwZone-it Forum
 
  FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups  
    RegisterRegister -->   LoginLogin  
WYSIWYG Html Editor  
DwZone Forum Index -> WYSIWYG Html Editor

Moderators: AdministratorsModerators 
Hint: For improved responsiveness, use Internet Explorer 4 (or above) with Javascript enabled, choose 'Dynamic' from the View dropdown and hit 'Set Options' to save your changes.
New Topic Search for
 View     Per page     Messages Since 
Messages 701 to 710 of 903 (Total: 371) First |  Prev |  Next |  Last  
 Subject Author Date  
   Re:Do I need to upload ALL files?  
View this persons public profile  gianluigi   22:24 13 Nov 2005  
   Re:Do I need to upload ALL files?  
View this persons public profile  [email protected]   23:29 13 Nov 2005  
   BR or P not saved?  
View this persons public profile  [email protected]   21:21 13 Nov 2005  
   Re:BR or P not saved?  
View this persons public profile  gianluigi   21:47 15 Nov 2005  
    A "security improvement" suggestion  
View this persons public profile  [email protected]   19:36 13 Nov 2005  
 
Hi again
In one application of mine - a sort of "Private Messenger" for an Intranet - I use the standalone upload feature for links, images and Flash: that's because I don't want the users to browse for files that were uploaded by other users

But here comes the trick: let's suppose one user to upload a file named "Document.doc"... let's suppose that a file with this name yet exists, so the uploaded file will be renamed to "Document(1).doc" and the user will get an alert about the rename

Let's also suppose that this user is a kind of ba***rd [:D]: moved by curiosity, he'll download and save the (maybe private) original "Document.doc" file, because now he knows that a file with this name exists... not good...

If you think this is not a dummy feature, maybe you can implement an automatic and more secure rename of ALL uploaded files (with an option in the editor setup to choose this feature or not): for example, the uploaded files could contain the upload Date in ISO format, something like "Document_20051113192304.doc", and it will be VERY hard for curious users to gain access to documents they shouldn't...

Just a suggestion, though...
Thanks!
 
Reply to this current thread  View this persons public profile  Send Private Message
   Re:A "security improvement" suggestion  
View this persons public profile  gianluigi   20:00 13 Nov 2005  
   Setup resize option in the standalone upload  
View this persons public profile  [email protected]   19:14 13 Nov 2005  
   Re:Setup resize option in the standalone upload  
View this persons public profile  gianluigi   19:57 13 Nov 2005  
   Windows SP2?  
View this persons public profile  [email protected]   0:54 9 Nov 2005  
   Re:Windows SP2?  
View this persons public profile  gianluigi   8:07 10 Nov 2005  
Last Visit: Monday 14 Jul, 2025 11:42 am First |  Prev |  Next |  Last  
 Login
Username:  Password:    
Read Message Read Message   Unread message Unread message
Read message [popular] Read message [popular]   Unread message [popular] Unread message [popular]
Read message [locked] Read message [locked]   Unread message [locked] Unread message [locked]
All times are GMT-2

Jump to: