A
A
Alexander Ivanov2017-01-23 13:24:20
PHP
Alexander Ivanov, 2017-01-23 13:24:20

How to prohibit uploading files with .php extension to Bitrix?

I noticed that in Bitrix viruses can get through the bootloader.
Is it possible to limit the available permissions for uploading to Bitrix and where?
For example: in MODX I can put a list of permissions that can be loaded .jpg, .png, .gif, .svg, etc.
ps thanks for the sympathy

Answer the question

In order to leave comments, you need to log in

3 answer(s)
A
Arseny Sokolov, 2017-01-23
@cimonlebedev

Here it is configured, but it all depends on custom modules, they may have vulnerabilities.
nAyQq3Ki6vZPAZ.png

A
Andrey Nikolaev, 2017-01-23
@gromdron

There are also settings for the "File" type field, in infoblocks - you can also set a list of extensions there

A
Adamos, 2017-01-23
@Adamos

Когда настроите - возьмите файл index.php, переименуйте его в index.php.jpg и проверьте, чего стоят эти настройки.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question