I am definitely all for removing the exclude files option and just going with allowfiles if everyone can live with it. It's definitely the safest way to go because like discussed earlier if you have you are using exclude files and your webhost adds some new extension that you don't know about it could open up a new exploit. A good starting point for allowfiles would just be .txt,.gif,.jpg.zip. Then you could add certain filetypes that you need to let people upload but want cause security issues.

Lumpy, it's not necessarily the filename but the extension that causes the problem. Normally the extensions can't be changed because if they are things like .gif/.jpg files then people upload these so they can link to them from the message itself.

-------------------
Rick Baker
UBBThreads developer