Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Securing file access |
|---|---|
| Date: | Wed, 29 Sep 2004 09:47:05 -0400 |
You could have the script create a temporary link to the file with a random filename, IE: ln -s <source file> 123456789randomcharacters.ext Then, redirect the user to the temporary link (which, if you use enough random characters, nobody should be able to guess), and have a scavenger program run every few minutes or so to delete any links that are older than a few minutes. J. Saphyr wrote on 9/28/2004, 2:15 AM:
guess a file name to download). In order to access the files, thedatabasewould link a file to a unique id, so a page that validates the userwouldthen give access to the file stored outside of the www on theserver. Now,this is where the real question lies. How is this possible sincethe filesare not in a www accessible path, since a mere link to a file won'tdue.Any thoughts would be welcome.Hi there. According to your files sizes, could you consider using binary fields in your database ? .antoine ------------oOoo---Ôô----ooOo--------------------------- Antonio FONTES (well, me, actually) http://www.nxtg.net/saphyr/ (tout et rien en français) http://www.nxtg.net/is/ (blog - développeur web) E-mail: prenom.nom@mondomaine.net -------------------------------------------------------------
-- ---------------------------------------------------- Jason Merriman Systems Administrator, America Online aim: jasonmerriman11 ----------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: CHM file download, Sandeep Singh Rawat |
|---|---|
| Next by Date: | RE: Securing file access, Booth, Simon |
| Previous by Thread: | Re: Securing file access, Saphyr |
| Next by Thread: | Re: Securing file access, Ian |
| Indexes: | [Date] [Thread] [Top] [All Lists] |