May 7, 201115 yr Hello, ive searched everywhere for this but not had the slightest luck (n) but anyway is it possible to have an image on my server so that it is only able to be displayed by the php script, but so that users cant view the image by URL for example myserver.com/images/pic1.jpg << so they wouldnt be able to view it that way? Thanks, Gary
May 7, 201115 yr Sure. You'll need to disable access to that folder using a .htaccess file if you're using apache, then create your script to process and output them. If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder
May 7, 201115 yr Author Sure. You'll need to disable access to that folder using a .htaccess file if you're using apache, then create your script to process and output them. If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder thanks for the reply, is there any chance you could point me in the right direction for the .htaccess way as im using apache, Thanks
May 7, 201115 yr Author http://httpd.apache.org/docs/2.0/mod/mod_access.html#deny thanks for that ive found another website handy for .htaccess aswel for any other viewers http://corz.org/serv/tricks/htaccess2.php found my answer now, although a little further help is required, im just wondering if .htaccess has a default of whats actually in it? i cant physically see the file on my server as when i upload the .htaccess file it uploads and disappears, i know the .htaccess script ive added is doing its job, im finding it rather hard to explain this haha lets pretend i just got my server, and the .htaccess file is there unedited, has it got a default of what the .htaccess file does? like any redirect rules or restrictions? im just wondering because now if ive edited it, may it now leave an easy access for hackers or something?
May 7, 201115 yr Files and folders that are named with a . in front of them in linux are hidden. You should be able to set your FTP to show hidden files. There is no default for apache unless your hosting has set something. Either way, if you've not set anything before chances are you'll be fine. Generally anything hosts want to block they will do so at a level above your account
May 7, 201115 yr Author Files and folders that are named with a . in front of them in linux are hidden. You should be able to set your FTP to show hidden files. There is no default for apache unless your hosting has set something. Either way, if you've not set anything before chances are you'll be fine. Generally anything hosts want to block they will do so at a level above your account so no need to bother with rewrite rules for hackers like something like this i found ? RewriteCond %{HTTP_USER_AGENT} ^BackWeb [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^Bandit [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BatchFTP [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BecomeBot [NC,OR] RewriteCond %{HTTP_USER_AGENT} ^BlackWidow [NC,OR] # etc.. RewriteCond %{HTTP_USER_AGENT} ^Net\ Vampire [NC] # why not come visit me directly? RewriteCond %{HTTP_REFERER} \.opendirviewer\. [NC,OR] # this prevents stoopid cross-site discovery attacks.. RewriteCond %{THE_REQUEST} \?\ HTTP/ [NC,OR] # please stop pretending to be the Googlebot.. RewriteCond %{HTTP_REFERER} users\.skynet\.be.* [NC,OR] # really, we need a special page for these ****s.. RewriteCond %{QUERY_STRING} \=\|w\| [NC,OR] RewriteCond %{THE_REQUEST} etc/passwd [NC,OR] RewriteCond %{REQUEST_URI} owssvr\.dll [NC,OR] # you can probably work these out.. RewriteCond %{QUERY_STRING} \=\|w\| [NC,OR] RewriteCond %{THE_REQUEST} \/\*\ HTTP/ [NC,OR] # etc.. RewriteCond %{HTTP_USER_AGENT} Sucker [NC] RewriteRule . abuse.txt [L]
May 7, 201115 yr Author You don't NEED to do it, but there's no reason why you can't hmm, i dont see why not any chance you could explain the above code slightly in more detail?
May 7, 201115 yr Author after half an hour of thinking the .htaccess was doing what i wanted to do it wasnt, it was working because i hadnt reloaded the page fully, i had refreshed but not reloaded (images etc), is there anyone who could resolve this ever so endless problem for me haha all i need is to deny any direct access in the images folder but so that my scripts can still get the images from the folder to display Thanks
May 8, 201115 yr get php to direct headers as an image. but make the phpscript die if its not loaded in the exact way you want it to. for instant. call image like .php?img=dddsassr23wrwerwerwefr and php is something like <?php if ($_GET == "dddsassr23wrwerwerwefr"){ header('Content-Type: image/gif'); readfile('path/to/myimage.gif'); } ?> completely theoretical, i have not tested this. this would only throw people for a little bit. Edited May 8, 201115 yr by PhilipMClifton
May 8, 201115 yr edit, u would have to put an rule looking for the redirection to the page if u wanted the script to die when directly looked at.
May 9, 201115 yr Hello, ive searched everywhere for this but not had the slightest luck (n) but anyway is it possible to have an image on my server so that it is only able to be displayed by the php script, but so that users cant view the image by URL for example myserver.com/images/pic1.jpg << so they wouldnt be able to view it that way? Thanks, Gary The short answer to this is "no". Stand back for a minute and think about how you are going to do this: you will probably want to use an <img src="..." /> tag in your HTML. The src attribute has to be a URL of a publicly accessible resource - i.e. it is impossible to give the user access to the image without it having a URL it can be found at! You're basically wanting a resource which needs to be accessible, not to be accessible... errr... see the problem? Perhaps you should look at authentication/authorisation - so that the image always exists at the URL, but access is denied if the user is not logged in? If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder Placing outside the Web root will ensure the image is never available via your Web server - you would never be able to access it through a URL without using a controller script to fetch the file from disk and present it at another URL (this is highly inefficient, as the file has to be read from disk into RAM, using CPU, and then out to network - Web servers tend to serve static content using sendfile or similar to copy directly from disk to network without all the intermediate processing). Possible solution: If you don't want to use authorisation, then off the top of my head one solution is to use a PHP controller which is used to fetch the images from disk. Each time you need an image, ask the controller to generate a one-time secret key which maps to an image on disk. Then use the secret key as the argument to your controller in the img src URL generated into the HTML page. The controller will return the image on the first request for the key, then destroy the key-image mapping. So if it were called for a second time, the key would not be found and it would return a 404. BUT this is useless in practise to protect an image from theft as anyone can still download to their hard drive if they know their way around browsers, caches and various simple HTTP tools. Not sure what exactly you're trying to achieve, but the general rule is that if you give any access for something to somebody, then they can always steal it by one means or another! The only way to have complete security is to prevent anyone ever looking at something - which usually defeats the entire point!
May 9, 201115 yr Placing outside the Web root will ensure the image is never available via your Web server - you would never be able to access it through a URL without using a controller script to fetch the file from disk and present it at another URL (this is highly inefficient, as the file has to be read from disk into RAM, using CPU, and then out to network - Web servers tend to serve static content using sendfile or similar to copy directly from disk to network without all the intermediate processing). I think one of us (and I'm not sure which) is missing the point of what the OP is trying to do. My take on it was that the OP wants to put the script in place to show an image based on a script. For example, it might be the OP wants to record data for each image being accessed in a database, or check the current session that the user is an admin before displaying the picture. This sort of thing would require some kind of intervention before the image is displayed, and isn't very easy to do any other way. Sure you can use Auth, but it's not quite as easy as a general php session. And yes, web stats like awstats can provide analytical stats, but not everyone can spend time delving into how it works etc, pulling the right data and using it themselves Anyway, from what I have read from your take on the script, the OP wants to basically make a script with an <img> tag in the html, and protect it if necessary. Upon re-reading the OP, it does kind of sound that way, but the final bit about viewing by URL is what made me think the above, so now I'm not sure either way Also, I'm just thinking, wouldn't sendfile be possible to use via a php script (providing it had shell access of course) to send the file only when certain parameters are met, keeping cpu and the memory footprint down to a minimum?
May 9, 201115 yr Also, I'm just thinking, wouldn't sendfile be possible to use via a php script (providing it had shell access of course) to send the file only when certain parameters are met, keeping cpu and the memory footprint down to a minimum? Yes, you can use the X-Sendfile method to do that, with PHP first handling the authentication etc. Obviously if the PHP bit isn't doing something critical or amazing, then it's slowing the process down though; useful, but definitely not a replacement for the Web server serving static resources directly.
May 9, 201115 yr Interesting stuff, I've not used sendfile before. I'll have to give it a whirl sometime. Thanks for the reference
May 9, 201115 yr @jay You use Zend Framework right? There is a nice action helper for serving file downloads via x-sendfile on github - https://github.com/noginn/noginn/blob/master/Noginn/Controller/Action/Helper/SendFile.php
May 9, 201115 yr Author @jay You use Zend Framework right? There is a nice action helper for serving file downloads via x-sendfile on github - https://github.com/noginn/noginn/blob/master/Noginn/Controller/Action/Helper/SendFile.php is it possible to use that in php 4? as i dont know php 5
May 9, 201115 yr You need PHP5 for Zend Framework, but you dont need PHP5 to use x-sendfile. You can use PHP 4 as long as mod_xsendfile its installed on your apache server you can use the following... header('Content-Disposition: attachment;filename=secret.png'); header('X-Sendfile: /path/to/secret.jpg');
May 11, 201115 yr Author You need PHP5 for Zend Framework, but you dont need PHP5 to use x-sendfile. You can use PHP 4 as long as mod_xsendfile its installed on your apache server you can use the following... header('Content-Disposition: attachment;filename=secret.png'); header('X-Sendfile: /path/to/secret.jpg'); so what would mod_xsendfile do when i install on my server? i dont quite get how this sendfile works
Create an account or sign in to comment