AFAIK, there's no umask for filenames, so if someone has write access, they can store anything they want.
You'd have to write a script to run from root cron to remove those files. To be safe, don't rely on file extensions; these are optional in *nix. Use the 'file' cmd to check the content.
|