Having problems with your account or logging in?
A lot of changes are happening in the community right now. Some may affect you. READ MORE HERE
Highlighted
Contributor.. Bill Hassell Contributor..
Contributor..
850 views

Major attachment problems

Apparently Lithium has a list of acceptable filenames based on the extension. A file with no extension is (silently) given the extension .wht as in abc.wht. Then posting with this attachment fails with no warning message. Instead the edit window reappears with the attachment box cleared.

 

>> Updated 7/1/11: I did not see abc.wht, all I saw was the editor refreshing with no error message.

 

This is a major problem for HP-UX, Linux, and other Unix variants which have nothing in common with PC-like extensions. An attachment should never be trusted by its extension. In the PC world, it is common to rename a .exe file as a .jpg or .doc file extension. Instead, every attachment should be screened as to its content. Files without an extension could be limited to ASCII content. Binary files (any extension) should be identified as to content using magic numbers (a Unix term for standard patterns) and rejected if there is a mismatch or undefined content.

 

But most important, the editor should report an error when rejecting an attachment plus an online help tag to explain the error and requirements.



Bill Hassell, sysadmin
Tags (2)
0 Likes
1 Reply
Acclaimed Contributor.. BGroot Acclaimed Contributor..
Acclaimed Contributor..

Re: Major attachment problems

We looked at this and due to security reasons we are not going to allow files without an extension. In addition, there is considerable documentation of people creating .php files and removing the extensions and running them (since browser treat files differently than the standard O/S kernel). If you want to attach a file that has no extension, then please append it to a .txt extension. Another possibility is to zip the file then you don't have to append the file extension.

 

I realize that the Unix/Linux world  is different then the PC world.

 

I will contact Lithium regarding issuing an error message when a file attachment is not performed correctly.

Micro Focus Software Support

The views expressed in my contributions are my own and do not necessarily reflect the views and strategy of Micro Focus.

If you find this or any post resolves your issue, please be sure to mark it as an accepted solution.
Tags (1)
0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.