Show HN: Upload any file
updrop.it
updrop.it
In fact, I found everything about your server.
Why? Because you, sir, do not know a thing about server security and configuration - this is the file I managed to upload: http://updrop.it/uploads/info.php
I will not hack your server but someone else definitely will, so you have to either close this hole ASAP (disable PHP file uploading) or take the service down.
When they did, everybody was like "oh, how can such crappy code power a successful service like that?"
Security is very important, but totally unrelated to good business sense. :)
Although, until filename(1), (2) etc issue is fixed, this service isn't worth any serious consideration anyway. Too many newbie mistakes here.
Update: this seems to be fixed too for now (not a perfect variant, as the original name is lost forever, but a plausible solution that's much better than it was). Nice!
Or do I need to post my message on the index page of your site for you to get how critical the vulnerability is? If so, which one? Updrop.it, torrbin.com or noteworthyfacts.com?
Since you're learning right now, find a framework (best if not PHP, but it can be a PHP framework) and follow the tutorial. You'll learn some "backend", and you'll learn it with best practices and with things in the right place.
Just a look at rtu.js made me cry. Never mix logic and presentation. Especially in such security-crucial projects.
I don't know what is the server side written in but it seems horrible too: I managed to upload the same file twice and returned a link in the same directory but with different names (boomer.mid and boomer(1).mid). So it's possible to flood all the server space with the same file unlimited amount of time. This is definitely a security issue. Also, a name mustn't change over time: my (or anyone else's) next boomer.mid upload mustn't become boomer(2).mid.
I haven't tried it yet but I hope server-side filetype validation is also present? Otherwise the server is going to have big troubles over time...