Re: secure file uploads and downloads
- From: Jerry Stuckle <jstucklex@xxxxxxxxxxxxx>
- Date: Mon, 17 Dec 2007 22:13:51 -0500
Steve wrote:
"Jerry Stuckle" <jstucklex@xxxxxxxxxxxxx> wrote in message news:Zd-dnVuLcOXoavvanZ2dnUVZ_u7inZ2d@xxxxxxxxxxxxxxSteve wrote:"Jerry Stuckle" <jstucklex@xxxxxxxxxxxxx> wrote in message news:ReOdnUOsIs3vaPvanZ2dnUVZ_ubinZ2d@xxxxxxxxxxxxxxBackpedaling again, troll. Let's see you hijack ANY PHP session of mine. Say on SourceForge? Or any other major site?Steve wrote:give me such a system and i'll be more than happy to."Jerry Stuckle" <jstucklex@xxxxxxxxxxxxx> wrote in message news:A8idnRGGZqmzc_vanZ2dnUVZ_rCtnZ2d@xxxxxxxxxxxxxxAh, let's see how you do it, troll.Dave wrote:and it works like a charm...right up to the point when i hijack your session.Hello,Dave,
Not sure if this is php related or not, but i'd like to have certain users who have the ability to upload files to my site, and others to download files.
I thought about .htaccess and basic authentication, but then i thought that's not very secure i was wondering if there was a php solution, something that splits user uploads and downloads in to two separate sections? I checked out some scripts on phpbuilder.com but they don't seem to work with php5 which is what i'm using.
Thanks.
Dave.
Sure, it's rather easy to do. You obviously have some sign-on capability on your site. Have two flags stored somewhere (i.e. database or where ever else you keep your user info). One flag says allow uploads, the other says allow downloads.
When they log in, store their login information (i.e. user id) in the $_SESSION variable. You could also store the flags in $_SESSION; it's up to you. I might do that because they're so small.
in case you missed it, i said 'ok'. give me a site that implements your suggestion and i'll be happy to. backpeddling, you illiterate twit, would involve me saying, no, i won't do it. you should know that though since you do it so often yourself.
Not at all. You said you could hijack my session. If you can hijack that session, you can hijack ANY session. Let's see you do it, troll.
No backpedaling. Just challenging you to do it. And not limiting it to any special session - ANY session will work.
--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@xxxxxxxxxxxxx
==================
.
- Follow-Ups:
- Re: secure file uploads and downloads
- From: Steve
- Re: secure file uploads and downloads
- References:
- secure file uploads and downloads
- From: Dave
- Re: secure file uploads and downloads
- From: Jerry Stuckle
- Re: secure file uploads and downloads
- From: Steve
- Re: secure file uploads and downloads
- From: Jerry Stuckle
- Re: secure file uploads and downloads
- From: Steve
- Re: secure file uploads and downloads
- From: Jerry Stuckle
- Re: secure file uploads and downloads
- From: Steve
- secure file uploads and downloads
- Prev by Date: Re: php ftp upload problem
- Next by Date: Re: Need advices in choosing approach
- Previous by thread: Re: secure file uploads and downloads
- Next by thread: Re: secure file uploads and downloads
- Index(es):
Relevant Pages
|
|