note 50348 added to function.header
| From: | jukkissh at hotmail dot com | Date: | Fri, 25 Feb 2005 11:04:37 +0000 |
| Subject: | note 50348 added to function.header | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-85528@lists.php.net to get a copy of this message | ||
If you are building a download script and you are afraid of someone exploiting it, I got a solution.
Store the information of the downloadable files into a (SQL or text file) database or even in array
variable in the code if your list of files is very static. You should store at least the path &
filename and unique id-number. You can be creative when thinking what info to store...
Build a download script that GETs an id number and checks the database for the file with the given
id. Then force download for that file, if it's found, otherwise print an error message.
Example use:
http://some.host.com/download.php?id=256
--> Downloading file...
http://some.host.com/download.php?id=h4x.txt
--> Error! File not found!
The force-download script can be built many ways stated in this page (in the notes at least). Pick
one that forces the download well. It does not need any extra security features, because we got them
already.
----
Manual Page -- http://www.php.net/manual/en/function.header.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+50348
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50348&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+50348&report=yes
Search -- http://master.php.net/manage/user-notes.php