You have exhaustive control over which file extensions can be posted. You can add and remove any file extension or MIME type, set width and height limits (for graphics) and file size limits.
I don't see how it is a security risk to allow people to post text files with a .PHP extension. There is absolutely no way for the code to be executed. It's no different than allowing people to attach C++ code or Rebol code snippets.
I can't speak about any pointless limitations in the attachment abilities of phpBB2.
I don't see how it is a security risk to allow people to post text files with a .PHP extension. There is absolutely no way for the code to be executed. It's no different than allowing people to attach C++ code or Rebol code snippets.
I can't speak about any pointless limitations in the attachment abilities of phpBB2.
Comment