<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nicola Moretti - Hanicker IT Blog &#187; file</title>
	<atom:link href="http://blog.nicolamoretti.com/tag/file/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.nicolamoretti.com</link>
	<description>Tecnologia e Digital Hacks</description>
	<lastBuildDate>Thu, 20 Oct 2011 23:04:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Upload sicuri con PHP</title>
		<link>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/</link>
		<comments>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 12:12:20 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[file]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[upload]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=122</guid>
		<description><![CDATA[<br/>Il caricamento di file su un server è una delle maggiori fonti di insicurezza per i siti web. Il documento che riporto, scritto da Alla Bezroutchko (ingegnere della sicurezza presso Scanit e persona presente da vari anni nel mondo della sicurezza con molti bug disclosures a proprio nome), rappresenta un vero vademecum per il caricamento tramite PHP. [...]]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/secure-file.png" ></a>Il caricamento di file su un server è una delle <strong>maggiori fonti di insicurezza</strong> per i siti web.</p>
<p style="text-align: center;"><img class="aligncenter" style="border: 2px solid black;" title="secure file" src="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/secure-file-300x63.png" alt="" width="300" height="63" /></p>
<p style="text-align: left;">Il documento che riporto, scritto da Alla Bezroutchko (ingegnere della sicurezza presso <a href="http://www.scanit.net/" >Scanit</a> e persona presente da vari anni nel mondo della sicurezza con molti bug disclosures a proprio nome), rappresenta un vero vademecum per il <strong>caricamento tramite PHP</strong>.</p>
<p>Link originale:</p>
<p><a href="http://www.scanit.be/uploads/php-file-upload.pdf" >http://www.scanit.be/uploads/php-file-upload.pdf</a></p>
<p>Se non funzionante, accedi direttamente al file <a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/php-file-upload.pdf" >cliccando qui</a>.</p>
<p>Personalmente, oltre ai soliti consigli, raccomando sempre di <span style="text-decoration: underline;">usare per i file caricati un nome casuale</span>, associato a quello del file caricato tramite php. Quando possibile, <span style="text-decoration: underline;">posizionare i file fuori dalle directory accessibili</span> (o bloccarne l&#8217;accesso diretto tramite le configurazioni di Apache) e accederne tramite php. Quando non possibile, <strong>controllare il contenuto dei file caricati, bloccare l&#8217;esecuzione di script nella cartella dedicata all&#8217;upload, verificare accuratamente le impostazioni di apache</strong>.</p>
<div></div>
<p><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_twitter" href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a><a class="a2a_button_stumbleupon" href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a><a class="a2a_button_google_reader" href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a><a class="a2a_button_orkut" href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_button_myspace" href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><a class="a2a_button_technorati_favorites" href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a><a class="a2a_button_yahoo_bookmarks" href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_netlog" href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;title=Upload%20sicuri%20con%20PHP" id="wpa2a_2"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

