Dummy rights problems with Plesk

From: Christian Giordano (christian_at_urmomlikesspam.com)
Date: 03/30/05


Date: Wed, 30 Mar 2005 10:04:45 +0000 (UTC)

Hi guys, I've an hosting in media temple (appliance-server) with plesk
7.5.1. I'm trying to bring make a CMS I did in another server to work
there. The issues is related the file uploading, in fact a dummy script
like that:

$newname="ciro.jpg";
$uploaddir="test_folder/";
copy($file, $uploaddir.$newname);
unlink($file);

in media temple doesn't work, it seems it arrives no file from the
upload html page. Obviously this script works fine in the other server.
At the beginning they told me that was an issue related to the safe_mode
that was ON. So I turned it off and restarted the machine. From the
phpinfo it seems I did correct:

http://www.delete-uk.com/info.php

Their assistance, very weak, can't help me further... does anyway have
an idea on how to upload files in that bloody server?

Thanks a lot, chr



Relevant Pages

  • Re: File Upload - Security Issues
    ... You want to upload a file for what reason and ... these viruses have less chance of being able to execute (even if succeeded ... :> file and what pitfalls you see re: security might be helpful on this ... :>: files to an IIS server that doesn't have MS Office actually installed? ...
    (microsoft.public.scripting.vbscript)
  • Re: File Upload - Security Issues
    ... uploaded and the user could upload any or all of these in theory. ... There is no one product that can give you 100% security, ... > Code doesn't execute in local memory space unless remote user has rights ... > You don't have MS Office installed on the server. ...
    (microsoft.public.scripting.vbscript)
  • pure-ftp nologin
    ... I have a server running FreeBSD 6.3. ... # If you want to enable PAM authentication, ... AnonymousCanCreateDirs no ... # Disallow anonymous users to upload new files ...
    (comp.unix.bsd.freebsd.misc)
  • [NT] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Collaboration Server is "a full-featured and integrated mail and instant ... attachment upload feature that may be exploited to upload files to ... * DeskNow Mail and Collaboration Server version 2.5.12 and prior ...
    (Securiteam)
  • Re: [Full-disclosure] phpBB 2.0.17 (and other BB systems as well) Cookie disclosure exploit.
    ... app that allows the user to upload an image of some type. ... Internet Explorer ignores the content type sent by the web server and ... > HTML code instead. ... > upload it as a phpBB avatar. ...
    (Full-Disclosure)