    Hi, I&#039;ve got an ASP page allowing people to upload, but want to make sure I cover my butt and not allow anyone to upload anything nasty. The upload page does require a login, but I&#039;d still like to know what kinds of file types I should be concerned about, and how I might go about excluding them.<BR><BR>I can&#039;t find any security info in the Upload FAQs - am I blind? If not, could someone help out?<BR><BR>Thanks,<BR>Mike

    &#062; what kinds of file types I should be concerned about<BR><BR>that depends what your server is configured to run. if your server supports perl, for example, you should probably disallow .pl files<BR><BR>always block .exe, .bat and .com files. if this is asp, you should probably block .asp files and the aliases thereof (check under app mappings)<BR>

