Securing My Site So Only Registered Users Can Download Files
Nov 14, 2007
I'm setting up a web site for my online music library, doing it the hard way and learning as I go!
What I want to do I keep all the audio files secure so only registered users can get at them, how do I do this? FTP? permissions? Can I pass the user data from the client database somehow or do I have to set it up manually for each client?
I'm using php and mysql and have a table set up with all the file locations in it and that side of things is mostly working well. Once a user gets the URL of the file how do I make sure only that user can download the file?
I've tried searching the web for info but I have the sneaking suspicion I'm not asking the right question.
In an environment where there is no webmail enabled for hosted sites and no sites have registered names (eg; they all belong in "our name space"), what is the affect of NAMED not running?
One affect that I have seen is with Site Scheduled Tasks that need URL resolutions. This appears to fail if Named is not running. All OTHER site content seems to work just fine. Apparently even in WordPress Multi-user/site situations.
I FULLY understand bind/named (and /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf), but it seems that it some cases, virtual hosted sites do not need Named (active) to function. This is NOT a case of incorrect DNS definitions created by Plesk for any hosted site.
SO - what is the "affect" of Named NOT running in a PLesk-12 Linux environment - not only for hosted sites but also the Plesk server itself?
I'm using oscommerce on a PHP5/Apache 2 installation. I've got several virtualhosts, and I'm using webmin to administrate them. I've just moved to this new server, and now files are being played in browser instead of downloaded....I thought I had changed the mime.types file correctly, but obviously not...
Here is the content of it: Code:
# This is a comment. I love comments.
# This file controls what Internet media types are sent to the client for # given file extension(s). Sending the correct media type to the client # is important so they know how to handle the content of the file. # Extra types can either be added here or by using an AddType directive # in your config files. For more information about Internet media types, # please read RFC 2045, 2046, 2047, 2048, and 2077. The Internet media type # registry is at [url].
I'm running a remote dl site where user will request a file from various file sharing site like rapidshare and megaupload, and allow it to stream and dl. Few days ago everything was normal, but since yesterday all rar files download have corrupt name and sizes but when trying to extract it seems to be corrupted, zip files are running fine though.
I am having trouble with moving my files to another server.
i have 1 servers, 1 hosting account (no ssh), both are using different control panel and i need to move all of the media files(movies) in the hosintg account to other server since hosting account contract will expire soon.
So, i am thinking of using FTP to transfer multiple files using mget command for FTP. But the thing is i will need to be there any press enter( to accept download) for every single files to be download. Which is very time consuming since i have hundred of files to move.
So my question is: 1/ is there a better way to move files in this situation?
2/ or Is there a shell script that i can use to download all of the file to my server without pressing enter accepting every single file?
I am searching for a reliable shared(or any other cheap option) hosting provider to host my mp3 download site. My site is getting 3000 uniques a day and monthly bandwidth usage is around 1000 to 1200 GB.
I run a download website boasting many files (entirely legal, non-pornographic), the sizes of which range from 100KB to 500MB. Some users of the site seem to be complaining of the files not downloading and or being truncated (i.e: it says it has been downloaded even though it has not been fully downloaded.)
Here is one reply I received:
"No specific massage appears, only sign the download is complete and infact it is not. About 7 mega down loaded instead of 79 mega. I use fire fox browser and ADSL internet line speed 512"
All the files however do seem to download perfectly on my computer, though I have a good 8mb line, which leads me to believe it may be something to do with a timeout setting?
I have a problem with users that want to download files that are in a protected folder. They don't get the login popup when the click on a link, if they use a direct url then they get the login but the download doesn't begin.
iPhone OS 7.12
Plesk Control Panel version: psa v8.4.0_build20080505.00 os_Windows 2003/2008 Operating systemMicrosoft: Windows 5.2;build-3790;sp2.0;suite272;product3
6 days ago, three users, one from Denmark, one from the UK and one from California - all reported connectivity trouble. I asked for tracert's from all three.
Two of them fail at 220.127.116.11 ( the California and Denmark one ) and one fails at 18.104.22.168
Both are GNAX servers.
I contacted Imhosted - and for 6 days they have ducked, dived, denied, and given me totally inappropriate stock replies ( such as asking me to check my IP address - when the actual affected IP addresses have already been supplied numerous times). They tried to fob me off saying it was an ISP issue ( two continents, at exactly the same time - yeah, right )
Imhosted have SAID, on two occasions, that they've contacted GNAX to have them fix the issue. So far, the problem remains for all three users.
Fortunately, we have a dedicated server of our own already, and we will be moving to it in the next few weeks. But meanwhile - what the hell can I do to rattle some sense into Imhosted and/or GNAX to get these poor guys back onto the site?
I've had three years of hell with Imhosted. Useless support, dreadful performance, unusable email, PHP and SQL issues - all in all, a dreadful experience.
I have a web site, where users sign up and edit there account settings using a web based form application.
These users will be uploading large files to my server, and as of right now they are uploading the files using a file upload form. The problem is it takes a really long time to upload them.
So my first question is will using ftp be significantly faster than using the web form http upload?
Assuming its faster to use ftp:
The big files that the user uploads get stored in a directory in the website directory right now, so that they would be accessible via www.mysite.com/user/files/ . There is an ftp account used to control that entire domain and all the files in it.
So if i were to create another ftp user, how would i go about allowing them to access a specific diretory in another users home directory.
Two days ago, Yahoo and hotmail users were receiving emails in the Junk folder. I thought this was due to the Reverse DNS settings not being set. So, I contacted Rus from cheapVPS and asked him to enable the Reverse DNS setting after I entered it in the Hyper VM panel, and he kindly did it.
Unfortunately, since the Reverse DNS setting was entered, Yahoo and Hotmail users stopped receiving mails from my site. Gmail users never faced any problem. the logs (from maillog) are as follows:
Code: Dec 6 00:37:27 aqarcenter,cin pop3d: LOGIN, firstname.lastname@example.org, ip=[::ffff:22.214.171.124] Dec 6 00:37:27 aqarcenter,cin pop3d: LOGOUT, email@example.com, ip=[::ffff:126.96.36.199], top=0, retr=0 Dec 6 00:40:00 aqarcenter,cin qmail: 1196890800.882846 new msg 12077935 Dec 6 00:40:00 aqarcenter,cin qmail: 1196890800.882881 info msg 12077935: bytes 2020 from <firstname.lastname@example.org> qp 11561 uid 48 Dec 6 00:40:00 aqarcenter,cin qmail: 1196890800.943863 starting delivery 308: msg 12077935 to remote email@example.com Dec 6 00:40:00 aqarcenter,cin qmail: 1196890800.943891 status: local 0/10 remote 1/20 Dec 6 00:40:02 aqarcenter,cin qmail: 1196890802.495781 delivery 308: success: 188.8.131.52_accepted_message./Remote_host_said:_250__<firstname.lastname@example.org>_Queued_mail_for_delivery/ Dec 6 00:40:02 aqarcenter,cin qmail: 1196890802.691249 status: local 0/10 remote 0/20 Dec 6 00:40:02 aqarcenter,cin qmail: 1196890802.918473 end msg 12077935
Dec 5 19:19:35 aqarcenter,cin qmail: 1196871575.358924 info msg 12077935: bytes 1970 from <email@example.com> qp 17875 uid 48 Dec 5 19:19:35 aqarcenter,cin qmail: 1196871575.536635 starting delivery 301: msg 12077935 to remote firstname.lastname@example.org Dec 5 19:19:35 aqarcenter,cin qmail: 1196871575.536673 status: local 0/10 remote 1/20 Dec 5 19:19:36 aqarcenter,cin qmail: 1196871576.006538 delivery 301: deferral: Connected_to_184.108.40.206_but_greeting_failed./Remote_host_said:_421_Message_from_(220.127.116.11)_temporarily_deferred_-_4.16.50._Please_refer_to_[url] Dec 5 19:19:36 aqarcenter,cin qmail: 1196871576.006641 status: local 0/10 remote 0/20 Dec 5 19:20:27 aqarcenter,cin qmail: 1196871627.155102 new msg 12077939 Dec 5 19:20:27 aqarcenter,cin qmail: 1196871627.155151 info msg 12077939: bytes 1970 from <email@example.com> qp 24088 uid 48 Dec 5 19:20:27 aqarcenter,cin qmail: 1196871627.604693 starting delivery 302: msg 12077939 to remote firstname.lastname@example.org Dec 5 19:20:27 aqarcenter,cin qmail: 1196871627.604744 status: local 0/10 remote 1/20 Dec 5 19:20:29 aqarcenter,cin qmail: 1196871629.172091 delivery 302: success: 18.104.22.168_accepted_message./Remote_host_said:_250__<email@example.com>_Queued_mail_for_delivery/ Dec 5 19:20:29 aqarcenter,cin qmail: 1196871629.172184 status: local 0/10 remote 0/20 Dec 5 19:20:29 aqarcenter,cin qmail: 1196871629.207391 end msg 12077939 and the site is aqarcenter.com
When you delete a site backup from its "Backup Manager" Panel, it is removed and no longer displayed in the Panel. However, I cannot tell if this action actually does anything with the real site backup files in "/var/lib/psa/dumps". Does this action merely remove it from PSA's database but not touch any actual files? If this is true, then how are site backup files supposed to be managed if this action doesn't actually delete them?
Basically we are unsure if becoming VAT registered when you do not need to is all that it's cracked up to be, what are your thoughts on all this?
To my understanding you don't have to be VAT registered until you earn 60K+ per year. Therefore is it worth it in the webhosting industry, because if you have more clients that means more VAT you have to pay each period (after outgoing deductions).
If we are in the industry that VAT customers pay is more than the VAT we can claim back as a company, is it really worth the hassel etc when it is not needed?
When I use website copy function the website files are copied to another domain but the database remains on old site. I use this function to move the website from devel state to the production state. All sites work fine but when i schedule the backups all databases are saved on old domain. How to move the database on production domain?
Just purchased a domain name and looking for hosting. Spent the last 2 nights reading reviews/complaints, but do not know which are genuine. Too many companies too pick from. Do not know which ones are good or to aviod.
I had a website with webhostingpad, but they couldn't get my webmail to work, so I cancelled. Apart from that, the service wasn't bad. Now hunting for a new web host.
Newbie, so don't need such big resources. Website is to promote a home school. A few pics and webmail that works is all I need. Site builder would be good too. Budget: about $5 a month. Location: Japan.
I have created a reseller account on my Cpanel dedicated and have 2 IPs to my customer to register them as name server. He has just done so. How can I make sure that he can use these new name servers on his customers' domains.
The name servers and the IPs are these: ns4.exeperu.com 22.214.171.124 ns3.exeperu.com 126.96.36.199
I have already bought my package with godaddy, so I want to get started as quickly as possible. As I go to enter my blogs URL at godaddy so I can create it, it keeps telling my the selected domain is invalid?
I am entering it in the correct place under 'Domain not registered here'. I think it would have something to do with my settings at 1and1 but I am lost
Basically I registered the domain www.technetnews.com with 1and1 and want to use it to host my blog with godaddy
DNS test . . . . . . . . . . . . . : Failed [WARNING] The DNS entries for this DC are not registered correctly on DNS se rver 'DNS.FIRST.IP.HERE'. Please wait for 30 minutes for DNS server replication. [WARNING] The DNS entries for this DC are not registered correctly on DNS se rver 'DNS.SECOND.IP.HERE'. Please wait for 30 minutes for DNS server replication. [FATAL] No DNS servers have the DNS records for this DC registered.
Server is a DC/AD. It has 2 IP's, both are static of course. the DNS Servers are manually added into the network configuration properties, as these are provided by the hoster.