Hacker News new | past | comments | ask | show | jobs | submit login

You should probably block EXE files for the safety of your users.



And .bat, .scr, .pif, .com? And .zip, .tar, .gz, .rar?

And then a shit load of file extensions that potentially run arbitrary code if you have the tool installed.

Seems kind of pointless.


Or they can just take the executable and change the extension. Extension-based blocking doesn't really work. However, these types of files generally have magic numbers in their headers that you could inspect to determine what they are.

Also, it'd be rather inconvenient if you couldn't upload a compressed archive to a file-sharing site.


It took just under 20 years for someone to re-create the core value of AOL to teenagers from the early/mid nineties.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: