XF 1.5 A simple question : Upload Gif Avatar could be hacked ?

ShinLim

Active member
Hello everyone,
I'm using ImageMagic Processor for my xenforo forum, not GD Image Library, and I must use ImageMagic because i'm using an addon which need ImageMagic
The thing I want to ask is if someone want to hack my website, is there any chance if he can hack by upload gif file type through avatar upload, or by attachment upload ?

Second question : Is there any setting to disallow use gif avatar while still using ImageMagic processor ?

Maybe this is a silly question and i know that, but I still want to ask :sick:
 
There's always a theoretical situation that there could be a vulnerability in PHP or a library used by it (GD, ImageMagick, etc). If you keep those up to date, then you're doing as much as you can to avoid any issue that could be caused by that.

There isn't an option to disable GIF processing when using ImageMagick.
 
There's always a theoretical situation that there could be a vulnerability in PHP or a library used by it (GD, ImageMagick, etc). If you keep those up to date, then you're doing as much as you can to avoid any issue that could be caused by that.

There isn't an option to disable GIF processing when using ImageMagick.
Thank you for your reply
You're a very experienced in coding, can you exploit it ?
 
Top Bottom