Hacker News new | ask | show | jobs
by Joakal 5533 days ago
Another is don't run PHP scripts in the uploads directory. [0].

[0] "Pass Non-PHP Requests to PHP." http://wiki.nginx.org/Pitfalls