<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Gravity Support Forums Topic: file upload security</title>
		<link>https://legacy.forums.gravityhelp.com/topic/file-upload-security</link>
		<description>Gravity Support Forums Topic: file upload security</description>
		<language>en-US</language>
		<pubDate>Mon, 20 Apr 2026 06:30:16 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.1</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>https://legacy.forums.gravityhelp.com/search.php</link>
		</textInput>
		<atom:link href="https://legacy.forums.gravityhelp.com/rss/topic/file-upload-security" rel="self" type="application/rss+xml" />

		<item>
			<title>trevor-in-alberta on "file upload security"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/file-upload-security#post-19786</link>
			<pubDate>Wed, 02 Mar 2011 20:06:07 +0000</pubDate>
			<dc:creator>trevor-in-alberta</dc:creator>
			<guid isPermaLink="false">19786@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Thanks!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Chris Hajer on "file upload security"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/file-upload-security#post-19474</link>
			<pubDate>Sat, 26 Feb 2011 22:48:58 +0000</pubDate>
			<dc:creator>Chris Hajer</dc:creator>
			<guid isPermaLink="false">19474@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;You can also configure your server so that directory indexes are turned off, and files in the directory are not listed.  To get to the file, the visitor would have to guess the name.  They can probably guess all the locations.&#60;/p&#62;
&#60;p&#62;On an Apache server, you can add this to a .htaccess file and put it /wp-content/uploads/ or /wp-content/ or even / if you want to turn off directory indexes across the whole site.  This will work if the server allows this type of override in at .htaccess file.  In any case, this is what to put in the .htaccess file (note the leading dot):&#60;/p&#62;
&#60;pre&#62;&#60;code&#62;Options -Indexes&#60;/code&#62;&#60;/pre&#62;
&#60;p&#62;At least that way the directory of files is not listed.  There's normally no reason to have directory indexes turn on in a WordPress installation.  And you can always override this rule to make the server show indexes for specific directories.&#60;/p&#62;
&#60;p&#62;This works if you are using Apache on Linux and the server is configured to allow this sort of override in the .htaccess file.  If you get a &#34;500 Internal Server Error&#34; (white screen) after adding this rule to you .htaccess file, the server probably does not allow it and this will not work for you.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kevin Flahaut on "file upload security"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/file-upload-security#post-19470</link>
			<pubDate>Sat, 26 Feb 2011 20:48:01 +0000</pubDate>
			<dc:creator>Kevin Flahaut</dc:creator>
			<guid isPermaLink="false">19470@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;You can use a filter to specify your upload location. Here's a previous thread with details.&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.gravityhelp.com/forums/topic/specify-upload-location#post-12459&#34; rel=&#34;nofollow&#34;&#62;http://www.gravityhelp.com/forums/topic/specify-upload-location#post-12459&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>trevor-in-alberta on "file upload security"</title>
			<link>https://legacy.forums.gravityhelp.com/topic/file-upload-security#post-19460</link>
			<pubDate>Sat, 26 Feb 2011 14:40:39 +0000</pubDate>
			<dc:creator>trevor-in-alberta</dc:creator>
			<guid isPermaLink="false">19460@https://legacy.forums.gravityhelp.com/</guid>
			<description>&#60;p&#62;Just got going with your products and so far I am very happy with your creation.&#60;/p&#62;
&#60;p&#62;One thing I noticed was with the file upload feature that the files are created in an insecure folder based on the form then date. When it is created it is based on the month without an index.html file in it.&#60;/p&#62;
&#60;p&#62;/wp-content/uploads/gravity_forms/1/2011/02&#60;/p&#62;
&#60;p&#62; This may seem nit-picky but for my application of the form I don't want people being able to poke around my folder so I will have to drop my own index.html files all over the place. Can you address my concern.... thank-you
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
