note 50348 deleted from function.header by danbrown
| From: | danbrown@php.net | Date: | Sun, 07 Dec 2008 18:28:30 +0000 |
| Subject: | note 50348 deleted from function.header by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-147825@lists.php.net to get a copy of this message | ||
Note Submitter: jukkissh at hotmail dot com
----
If you are building a download script and you are afraid of someone exploiting it, I got a solution.
Store the information of the downloadable files into a (SQL or text file) database or even in array
variable in the code if your list of files is very static. You should store at least the path &
filename and unique id-number. You can be creative when thinking what info to store...
Build a download script that GETs an id number and checks the database for the file with the given
id. Then force download for that file, if it's found, otherwise print an error message.
Example use:
http://some.host.com/download.php?id=256
--> Downloading file...
http://some.host.com/download.php?id=h4x.txt
--> Error! File not found!
The force-download script can be built many ways stated in this page (in the notes at least). Pick
one that forces the download well. It does not need any extra security features, because we got them
already.