- Posts: 4857
- Thank you received: 366
check upload for double extensions is not working
- Jose
-
- Offline
- Administrator
-
I have just send you an email with a modified file to detect all files with multiple extensions (not only php files), so this should solve your issue. I will also add this change to future versions of Securitycheck Pro.
Regards,
Jose
Please Log in or Create an account to join the conversation.
- yogitha
- Topic Author
- Offline
- New Member
-
- Posts: 8
- Thank you received: 0
Thank you very much for the support. We have applied the change sent to us. Looks to work now. We sent it to testing team.
with regard to csrf protection, the government security audit team warned this and recommended to prevent.
Kindly guide us on this topic.
Once again we thank you for the support being extended.
Please Log in or Create an account to join the conversation.
- Jose
-
- Offline
- Administrator
-
- Posts: 4857
- Thank you received: 366
You're welcome Yogitha!Thank you very much for the support. We have applied the change sent to us. Looks to work now. We sent it to testing team.
Csrf protection must be implemented for each extension; for instance, Securitycheck Pro adds protection agains this technique. So I fear this is a field where I can't help you so much. Anyway Joomla is secure enough and Securitycheck Pro also adds user session protection.with regard to csrf protection, the government security audit team warned this and recommended to prevent.
Kindly guide us on this topic.
Regards,
Jose
Please Log in or Create an account to join the conversation.
- yogitha
- Topic Author
- Offline
- New Member
-
- Posts: 8
- Thank you received: 0
Thank you for your support.Double extension is working only some of the combinations viz., doc.pdf, rar.zip etc... with the modified set up file. While uploading exe. pdf,exe.exe etc....., it is not working. please do the needful to avoid all type of double extensions uploading combination.
Regards,
Yogitha Sindhu
Please Log in or Create an account to join the conversation.
- Jose
-
- Offline
- Administrator
-
- Posts: 4857
- Thank you received: 366
Regards,
Jose
Please Log in or Create an account to join the conversation.
This site is not affiliated with or endorsed by the Joomla! Project. It is not supported or warranted by the Joomla! Project or Open Source Matters. The Joomla! logo is used under a limited license granted by Open Source Matters, the trademark holder in the United States and other countries.
We may collect your IP address and your browser's User Agent string while using our site for security reasons. This information is retained only until we check you're not trying to hack our website.