Yes, and yes, and you should do both under account with limited permission. You should also remove execute permission from image file.
You should also virusscan the files periodically. A good time would be when you update virus definitions.
This is reasonably everything that you can do.
In reply to Re: security: making sure graphics uploaded by users are safe
by Anonymous Monk
in thread security: making sure graphics uploaded by users are safe
by keiusui
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |