Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

images only readable through php script

Featured Replies

Hello, ive searched everywhere for this but not had the slightest luck (n) but anyway is it possible to have an image on my server so that it is only able to be displayed by the php script, but so that users cant view the image by URL for example myserver.com/images/pic1.jpg << so they wouldnt be able to view it that way?

 

Thanks, Gary

Sure. You'll need to disable access to that folder using a .htaccess file if you're using apache, then create your script to process and output them. If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder

  • Author

Sure. You'll need to disable access to that folder using a .htaccess file if you're using apache, then create your script to process and output them. If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder

 

thanks for the reply, is there any chance you could point me in the right direction for the .htaccess way as im using apache, Thanks

  • Author

 

thanks for that :) ive found another website handy for .htaccess aswel for any other viewers

http://corz.org/serv/tricks/htaccess2.php

found my answer now, although a little further help is required,

 

im just wondering if .htaccess has a default of whats actually in it? i cant physically see the file on my server as when i upload the .htaccess file it uploads and disappears, i know the .htaccess script ive added is doing its job, im finding it rather hard to explain this haha

 

lets pretend i just got my server, and the .htaccess file is there unedited, has it got a default of what the .htaccess file does? like any redirect rules or restrictions? im just wondering because now if ive edited it, may it now leave an easy access for hackers or something?

Files and folders that are named with a . in front of them in linux are hidden. You should be able to set your FTP to show hidden files. There is no default for apache unless your hosting has set something. Either way, if you've not set anything before chances are you'll be fine. Generally anything hosts want to block they will do so at a level above your account

  • Author

Files and folders that are named with a . in front of them in linux are hidden. You should be able to set your FTP to show hidden files. There is no default for apache unless your hosting has set something. Either way, if you've not set anything before chances are you'll be fine. Generally anything hosts want to block they will do so at a level above your account

 

so no need to bother with rewrite rules for hackers like something like this i found ?

 

RewriteCond %{HTTP_USER_AGENT} ^BackWeb [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^Bandit [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^BatchFTP [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^BecomeBot [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^BlackWidow [NC,OR]
# etc..
RewriteCond %{HTTP_USER_AGENT} ^Net\ Vampire [NC]
# why not come visit me directly?
RewriteCond %{HTTP_REFERER} \.opendirviewer\. [NC,OR]
# this prevents stoopid cross-site discovery attacks..
RewriteCond %{THE_REQUEST} \?\ HTTP/ [NC,OR]
# please stop pretending to be the Googlebot..
RewriteCond %{HTTP_REFERER} users\.skynet\.be.* [NC,OR]
# really, we need a special page for these ****s..
RewriteCond %{QUERY_STRING} \=\|w\| [NC,OR]
RewriteCond %{THE_REQUEST} etc/passwd [NC,OR]
RewriteCond %{REQUEST_URI} owssvr\.dll [NC,OR]
# you can probably work these out..
RewriteCond %{QUERY_STRING} \=\|w\| [NC,OR]
RewriteCond %{THE_REQUEST} \/\*\ HTTP/ [NC,OR]
# etc..
RewriteCond %{HTTP_USER_AGENT} Sucker [NC]
RewriteRule . abuse.txt [L]

  • Author

You don't NEED to do it, but there's no reason why you can't

 

hmm, i dont see why not :p any chance you could explain the above code slightly in more detail?

  • Author

after half an hour of thinking the .htaccess was doing what i wanted to do it wasnt, it was working because i hadnt reloaded the page fully, i had refreshed but not reloaded (images etc),

 

is there anyone who could resolve this ever so endless problem for me haha

all i need is to deny any direct access in the images folder but so that my scripts can still get the images from the folder to display

 

Thanks

get php to direct headers as an image.

 

but make the phpscript die if its not loaded in the exact way you want it to.

 

for instant.

 

call image like .php?img=dddsassr23wrwerwerwefr

 

and

 

php is something like

 

<?php

 

if ($_GET == "dddsassr23wrwerwerwefr"){

header('Content-Type: image/gif');

readfile('path/to/myimage.gif');

}

 

?>

 

 

 

completely theoretical, i have not tested this.

 

this would only throw people for a little bit.

Edited by PhilipMClifton

edit, u would have to put an rule looking for the redirection to the page if u wanted the script to die when directly looked at.

Hello, ive searched everywhere for this but not had the slightest luck (n) but anyway is it possible to have an image on my server so that it is only able to be displayed by the php script, but so that users cant view the image by URL for example myserver.com/images/pic1.jpg << so they wouldnt be able to view it that way?

 

Thanks, Gary

The short answer to this is "no". Stand back for a minute and think about how you are going to do this: you will probably want to use an <img src="..." /> tag in your HTML. The src attribute has to be a URL of a publicly accessible resource - i.e. it is impossible to give the user access to the image without it having a URL it can be found at!

 

You're basically wanting a resource which needs to be accessible, not to be accessible... errr... see the problem?

 

Perhaps you should look at authentication/authorisation - so that the image always exists at the URL, but access is denied if the user is not logged in?

 

If you'd rather an easier method than the .htaccess method, you could just stick the image folder outside of your web root folder

 

Placing outside the Web root will ensure the image is never available via your Web server - you would never be able to access it through a URL without using a controller script to fetch the file from disk and present it at another URL (this is highly inefficient, as the file has to be read from disk into RAM, using CPU, and then out to network - Web servers tend to serve static content using sendfile or similar to copy directly from disk to network without all the intermediate processing).

 

Possible solution: If you don't want to use authorisation, then off the top of my head one solution is to use a PHP controller which is used to fetch the images from disk. Each time you need an image, ask the controller to generate a one-time secret key which maps to an image on disk. Then use the secret key as the argument to your controller in the img src URL generated into the HTML page. The controller will return the image on the first request for the key, then destroy the key-image mapping. So if it were called for a second time, the key would not be found and it would return a 404. BUT this is useless in practise to protect an image from theft as anyone can still download to their hard drive if they know their way around browsers, caches and various simple HTTP tools.

 

Not sure what exactly you're trying to achieve, but the general rule is that if you give any access for something to somebody, then they can always steal it by one means or another! The only way to have complete security is to prevent anyone ever looking at something - which usually defeats the entire point!

Placing outside the Web root will ensure the image is never available via your Web server - you would never be able to access it through a URL without using a controller script to fetch the file from disk and present it at another URL (this is highly inefficient, as the file has to be read from disk into RAM, using CPU, and then out to network - Web servers tend to serve static content using sendfile or similar to copy directly from disk to network without all the intermediate processing).

 

I think one of us (and I'm not sure which) is missing the point of what the OP is trying to do. My take on it was that the OP wants to put the script in place to show an image based on a script. For example, it might be the OP wants to record data for each image being accessed in a database, or check the current session that the user is an admin before displaying the picture. This sort of thing would require some kind of intervention before the image is displayed, and isn't very easy to do any other way. Sure you can use Auth, but it's not quite as easy as a general php session. And yes, web stats like awstats can provide analytical stats, but not everyone can spend time delving into how it works etc, pulling the right data and using it themselves

 

Anyway, from what I have read from your take on the script, the OP wants to basically make a script with an <img> tag in the html, and protect it if necessary. Upon re-reading the OP, it does kind of sound that way, but the final bit about viewing by URL is what made me think the above, so now I'm not sure either way

 

Also, I'm just thinking, wouldn't sendfile be possible to use via a php script (providing it had shell access of course) to send the file only when certain parameters are met, keeping cpu and the memory footprint down to a minimum?

Also, I'm just thinking, wouldn't sendfile be possible to use via a php script (providing it had shell access of course) to send the file only when certain parameters are met, keeping cpu and the memory footprint down to a minimum?

Yes, you can use the X-Sendfile method to do that, with PHP first handling the authentication etc. Obviously if the PHP bit isn't doing something critical or amazing, then it's slowing the process down though; useful, but definitely not a replacement for the Web server serving static resources directly.

You need PHP5 for Zend Framework, but you dont need PHP5 to use x-sendfile. You can use PHP 4 as long as mod_xsendfile its installed on your apache server you can use the following...

 

header('Content-Disposition: attachment;filename=secret.png');
header('X-Sendfile: /path/to/secret.jpg');

  • Author

You need PHP5 for Zend Framework, but you dont need PHP5 to use x-sendfile. You can use PHP 4 as long as mod_xsendfile its installed on your apache server you can use the following...

 

header('Content-Disposition: attachment;filename=secret.png');
header('X-Sendfile: /path/to/secret.jpg');

 

so what would mod_xsendfile do when i install on my server? i dont quite get how this sendfile works

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.