• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Can you get the direct link?

I'm making a script where only registered users should be allowed to have access to a file and I want to make sure that the direct link can't be obtained.
 
I didn't have any luck in my quick cracking attempt. Although you ask a question that nobody can surely answer "no" to. There is no way to for us to prove that it is impossible-- just because we are unable does not mean that there is no way. Of course, if someone does find a way to obtain the path then that person can certainly answer "yes".

If the source code isn't a secret we may be able to better check the security of your script more thoroughly. Points of attack are always easier to find if you know what you are dealing with. If we can't crack it with the code, it is unlikely someone else will crack it without the code when you go to use it in your application.

For example, if your script copies the image requested to a temp folder, then offers it for download and then once the download is completed, it deletes the file. You would only have to worry about other people obtaining the path while one user with access is downloading the file. If on the other hand, your script feeds my browser the direct link then your script is at the mercy of your user's browser. Some browsers may display the path in the save file dialog box or whatever.
 
I couldnt get a direct link, but you can get the filename by looking at what download.php spits out

"HTTP/1.1 200 OK
Date: Sun, 25 Jun 2006 21:15:40 GMT
Server: Apache/1.3.34 (Unix) mod_perl/1.26
Content-Disposition: attachment; filename=image.jpg
X-Powered-By: PHP/4.3.10
Vary: NFInfo
Content-Type: image/jpg
X-Cache: MISS from picspace.net
Transfer-Encoding: chunked

339
►JFIF☺☺☺HHC♥♦♦♦♥♦♦♦♠
<jpeg file data>
0"

And since download.php directly spits out the image data, you can do this <img src=http://picspace.net/download.php> and it works.
download.php
 
That's not a problem right now. I just don't want the directory where the file is located to be made available easily, at least not for the average user.
 
Why not just put the file in a non http serving directory and use your php script to read its contents and spit it out, then there wouldnt be a link to get.
 
the contents of the php file are obscured so I think youve accomplished what you were looking to, just spits out ascii characters in order it looks like.
 
Kaos said:
the contents of the php file are obscured so I think youve accomplished what you were looking to, just spits out ascii characters in order it looks like.
How are you getting the PHP file itself?
 
mikeblas said:
How are you getting the PHP file itself?

If you copy the link and try to download it with a download manager, the php file gets downloaded instead.
 
fender said:
If you copy the link and try to download it with a download manager, the php file gets downloaded instead.

Or right cick on the "Click Here" link, choose save as, and it will download "download.php" which can then be renamed to .jpg.
 
As has been said earlier in the thread, the only sure-fire way to make sure nobody can access it is to put the file in a directory not accessible to Apache/Visitors, but is accessible to PHP, and serve it up.
 
CEpeep said:
As has been said earlier in the thread, the only sure-fire way to make sure nobody can access it is to put the file in a directory not accessible to Apache/Visitors, but is accessible to PHP, and serve it up.

How would you do that?
 
fender said:
If you copy the link and try to download it with a download manager, the php file gets downloaded instead.
What is a "download manager"?
 
fender said:
How would you do that?

Put the file in a place on your server that Apache doesn't have access to. Then instead of a PHP script pulling the file (red image) from where it is now, change the path to the inaccessible directory. Make sure PHP is running as a user that has access to the directory the file is in.
 
CEpeep said:
Put the file in a place on your server that Apache doesn't have access to. Then instead of a PHP script pulling the file (red image) from where it is now, change the path to the inaccessible directory. Make sure PHP is running as a user that has access to the directory the file is in.

How would you create such folder? I'm on a shered server, but I'd also like to know for dedicted as well.
 
fender said:
How would you create such folder? I'm on a shered server, but I'd also like to know for dedicted as well.

In order to do it for a shared server, make a directory you have access to, then use a .htaccess file to deny all connections to the directory and its contents. For a dedicated server, you just use any directory (or create a new one) that the Apache user doesn't have the permissions to access.
 
Back
Top