security bug? the .js files needs protection.

Upload core product.
Post Reply
rtcg
Posts: 1
Joined: Tue Nov 30, 2010 6:01 pm

security bug? the .js files needs protection.

Post by rtcg »

What is the recommended method to protect the applet_ftp.js file from being viewed from a direct http query?

After setting up the demo, I went to http://mysite.tld/jupload/applet_ftp.js and pulled up the parameters plain as day.

Yes I know that ftp is an insecure protocol and there are ways to hack most anything but I'm hoping to remove the low hanging fruit from the script kiddies.

User avatar
support
Posts: 1503
Joined: Sun Jan 27, 2008 6:19 pm

Re: security bug? the .js files needs protection.

Post by support »

You could obfuscate the JavaScript with a tool like:
http://www.javascriptobfuscator.com/default.aspx

But what do you want really protect? FTP login/password? Then see:
http://www.jfileupload.com/products/jfi ... aq.html#36

Post Reply