note 48538 added to function.header

From: Date: Tue, 28 Dec 2004 22:17:13 +0000
Subject: note 48538 added to function.header
Groups: php.notes 
Request: Send a blank email to php-notes+get-82422@lists.php.net to get a copy of this message
I just made a function to allow a file to force-download (for a script to disallow file links from untrusted sites -- preventing mp3/video leeching on forums), and I realized that a script like that could potentially be very dangerous. Someone could possibly exploit the script to download sensitive files from your server, like your index.php or passwords.txt -- so I made this switch statement to both allow for many file types for a download script, and to prevent certain types from being accessed. <?php function dl_file($file){ //First, see if the file exists if (!is_file($file)) { die("<b>404 File not found!</b>"); } //Gather relevent info about file $len = filesize($file); $filename = basename($file); $file_extension = strtolower(substr(strrchr($filename,"."),1)); //This will set the Content-Type to the appropriate setting for the file switch( $file_extension ) { case "pdf": $ctype="application/pdf"; break; case "exe": $ctype="application/octet-stream"; break; case "zip": $ctype="application/zip"; break; case "doc": $ctype="application/msword"; break; case "xls": $ctype="application/vnd.ms-excel"; break; case "ppt": $ctype="application/vnd.ms-powerpoint"; break; case "gif": $ctype="image/gif"; break; case "png": $ctype="image/png"; break; case "jpeg": case "jpg": $ctype="image/jpg"; break; case "mp3": $ctype="audio/mpeg"; break; case "wav": $ctype="audio/x-wav"; break; case "mpeg": case "mpg": case "mpe": $ctype="video/mpeg"; break; case "mov": $ctype="video/quicktime"; break; case "avi": $ctype="video/x-msvideo"; break; //The following are for extensions that shouldn't be downloaded (sensitive stuff, like php files) case "php": case "htm": case "html": case "txt": die("<b>Cannot be used for ". $file_extension ." files!</b>"); break; default: $ctype="application/force-download"; } //Begin writing headers header("Pragma: public"); header("Expires: 0"); header("Cache-Control: must-revalidate, post-check=0, pre-check=0"); header("Cache-Control: public"); header("Content-Description: File Transfer"); //Use the switch-generated Content-Type header("Content-Type: $ctype"); //Force the download $header="Content-Disposition: attachment; filename=".$filename.";"; header($header ); header("Content-Transfer-Encoding: binary"); header("Content-Length: ".$len); @readfile($file); exit; } ?> This works in both IE and Firefox. ---- Manual Page -- http://www.php.net/manual/en/function.header.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+48538 Delete -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes&reason=bad+code Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes&reason=spam Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes&reason=useless+example Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes&reason=contains+commercial+links Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+48538&report=yes&reason=useless+note Reject -- http://master.php.net/manage/user-notes.php?action=reject+48538&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#82422) next »