Help with security

This is a discussion on "Help with security" within the Website Planning section. This forum, and the thread "Help with security are both part of the Planning Your Website category.



 Subscribe in a reader

Go Back   Webforumz.com > Main Forums > Planning Your Website > Website Planning

Notices


Reply
 
LinkBack Thread Tools
  #1  
Old Apr 7th, 2007, 13:14
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Help with security

Hi,
I’m pretty new to forums, so I hope it’s ok just starting a new thread. Anyway, my question is about restricting access to the root directories of a website. I’ve recently created a website in which I mainly want to show photos to my friends, but I don’t want random people looking at them. At the moment you need to log in to view them, but it’s still possible to type the root address in the address bar and view the photos. Is there anyway I can stop people from doing that.
Well, thanks a lot!
Wiggles
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote

  #2  
Old Apr 7th, 2007, 13:15
Ryan Fait's Avatar
Elite Veteran
Join Date: May 2006
Location: Las Vegas
Posts: 3,787
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Welcome to the forums!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old Apr 7th, 2007, 13:19
Elite Veteran
Join Date: Jan 2007
Location: You know where
Age: 31
Posts: 4,617
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Welcome to the forumz!

So you have a login page then? You should make that the default page like index.php or aspx (or whatever extension you have).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4  
Old Apr 7th, 2007, 13:23
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Thanks for the welcome!
To karinne, that's true about having the login for the index, but (me being fussy) I have other photos on the website, and it's just these particular photos that I want to be private... Thanks a lot though, it was good thinking!
wiggles
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5  
Old Apr 7th, 2007, 13:26
Elite Veteran
Join Date: Jan 2007
Location: You know where
Age: 31
Posts: 4,617
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Ok so ... you must have a main index page with categories of photos then right? So you should make a section and call it private, just put the titles in and if people click on one of the link, then they get the login page.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6  
Old Apr 7th, 2007, 13:35
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Mmm, yeah, at the moment that's what happens, the trouble is that people can still type in the address bar, for example: http://fake/images/private/fake.jpg and view it. The login uses a cookie, but it only checks for a cookie on an actual page... not a file....
wiggles

edit: sorry I didnt think it would try and link that.... the address was an example.

Last edited by wiggles; Apr 7th, 2007 at 13:38. Reason: made a link that doesnt work
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7  
Old Apr 7th, 2007, 13:38
Elite Veteran
Join Date: Jan 2007
Location: You know where
Age: 31
Posts: 4,617
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Oh ... I see what you mean ... hmmm ... not sure then.

Maybe with .htaccess you can do something that if they type in that /private/ folder it sends them directly to a login page? I'm not too familiar on the workings of .htaccess... I'm just learning that stuff myself but I'm pretty sure that would be the way to go.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8  
Old Apr 7th, 2007, 13:41
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Oh OK, I'll have to look into that, I've never heard of it.
Mmm, well thank you so much for the help! I was hoping there might be a quick fix...(never is :P)
wiggles
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9  
Old Apr 7th, 2007, 16:38
Elite Veteran
Join Date: Sep 2006
Location: Pink House
Posts: 3,946
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Check and see if your webhost offers password protected pages? That might be a simple fix.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #10  
Old Apr 7th, 2007, 19:22
Ryan Fait's Avatar
Elite Veteran
Join Date: May 2006
Location: Las Vegas
Posts: 3,787
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Is there any way you could use PHP to print an image that's on the server, but not in a browser accessible place? That could be an option... if it's possible.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #11  
Old Apr 8th, 2007, 01:39
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Mmm, I'll have to ask about the password protected pages! Thanks
That's a good idea about printing the image, I'll have to look into that too! Thanks a lot!
Wiggles
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #12  
Old Apr 8th, 2007, 09:36
Most Reputable Member
Join Date: May 2006
Location: North West, UK
Age: 22
Posts: 1,173
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Can't you put the images in a database and make it so they can only be accessed after a user has logged in. Or is that what you said ryan?

Pete.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #13  
Old Apr 8th, 2007, 13:35
Ryan Fait's Avatar
Elite Veteran
Join Date: May 2006
Location: Las Vegas
Posts: 3,787
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

That's sort of related to what I said. It would work, I was just wondering if PHP could read an image and then display it on a page. You know, like putting the image in a location before the HTTP root and then using PHP to access it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #14  
Old Apr 8th, 2007, 23:44
New Member
Join Date: Apr 2007
Location: Australia
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Yea, both of those ideas are great! But I'm not really sure how to do databases, but I guess it's a great time to learn hey! Do either of you have any tips on how to do what you suggested?
wiggles
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #15  
Old Apr 8th, 2007, 23:58
Most Reputable Member
Join Date: May 2006
Location: North West, UK
Age: 22
Posts: 1,173
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

I'm lost with all that stuff (though I am getting better) but I can reccomend 2 books. First one (which is a little more friendly) is PHP and MySQL for Dynamic Websites (second edition) by Larry Ullman and the other is Web Database Applications with PHP and MySQL by Hugh E. Williams & David Lane. The first one is a Visual Quickpro Guide and the second is by O'Reilly.

The second one feels a little bit like your in a business meeting or something but I swear they are both great books it's just me that's a bit rubbish. Oh they're massive as well - the first one is about 700 pages and the second one nearly 800!

By the way, take a look at phpMyAdmin it's a GUI for MySQL and might simplify the database end of things or there is Cocoa MySQL for mac.

Pete.

Last edited by pa007; Apr 8th, 2007 at 23:58. Reason: spelling
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #16  
Old Apr 9th, 2007, 12:17
Ryan Fait's Avatar
Elite Veteran
Join Date: May 2006
Location: Las Vegas
Posts: 3,787
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

The PHP Bible is also a good read. I found The JavaScript Bible to be a bit easier to follow than the PHP version, though.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #17  
Old Apr 9th, 2007, 22:28
Most Reputable Member
Join Date: Apr 2006
Location: Cornwall, UK
Posts: 1,310
Thanks: 0
Thanked 0 Times in 0 Posts
Re: Help with security

Here's an idea off-the-cuff so to speak.

It assumes you can password protect pages or better still a directory but saves you having to get into database stuff.

Place the photos as images in pages and call them, e.g., photo1.inc, etc. Place these files and images in the protected directory also.

You can then use 'include' calls to include these pages.

Because they are in a protected directory, you should not be able to see them by directly addressing them in your browser's address bar.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
CMS Security ChrisTheSoul Web Page Design 5 Feb 21st, 2008 16:28
php security saltedm8 PHP Forum 22 Sep 27th, 2007 09:22
Security Ryan Fait PHP Forum 5 Nov 28th, 2006 12:22
Security cbrams9 JavaScript Forum 2 Sep 22nd, 2006 01:47


All times are GMT. The time now is 05:33.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC8
© 2003-2008 Webforumz.com : All Rights Reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42