Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-12-2007, 09:13 PM   #1
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
htaccess HELP!

I have a site/directory that I only want myself and my partner to be able to load up

I was going to use a deny all ip's but ours, but the issue is that we have other sites that pull images from this domain

so, how can I restrict anyone but us two from that domain, but allow images to be pulled from ANY domain from there?
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-12-2007, 09:14 PM   #2
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
basically, the issues is, we have an important control panel on that domain, and I want only us to access that control panel...it is already password protected to get into the control panel....but I still want that extra level of htaccess control to only allow our ip's
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-12-2007, 09:17 PM   #3
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,372
restrict the main url and let images directory be readable from all
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-12-2007, 09:17 PM   #4
mortenb
Confirmed User
 
mortenb's Avatar
 
Join Date: Jul 2004
Location: Denmark ICQ: 7880009
Posts: 2,203
Ignore me. I misread your post

Last edited by mortenb; 07-12-2007 at 09:19 PM..
mortenb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 12:59 AM   #5
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Or... put the control panel in a directory like,
58ju4Tg
and then restrict access in that directory.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:16 AM   #6
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by V_RocKs View Post
Or... put the control panel in a directory like,
58ju4Tg
and then restrict access in that directory.
well, the control panel is in a directory, but I want to block access to the entire domain

the images folder is WITHIN the control panel directory though
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:22 AM   #7
BV
wtf
 
BV's Avatar
 
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
maybe do a symbolic link of the images dir or move the control panel to another dir
BV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:23 AM   #8
Beaver Bob
Confirmed User
 
Beaver Bob's Avatar
 
Join Date: Aug 2005
Location: Las Vegas, NV
Posts: 1,099
why can't you just store the images somewhere else?
__________________
Spunky Dollars | Need Content?
Paysite Owners: Protect Your Members Area with Strongbox

361-574-229
Beaver Bob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:35 AM   #9
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
What types of images?
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:35 AM   #10
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by Beaver Bob View Post
why can't you just store the images somewhere else?
it is part of the control panel software and the software is zend encoded with no option to place them elsewhere
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:36 AM   #11
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
ie, just gif, jpg?
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:37 AM   #12
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by V_RocKs View Post
What types of images?
all types
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:39 AM   #13
Evil E
Confirmed User
 
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
slkfjaldika;ie';1190-9
__________________


A girl once told me "Give me 8 inches and make it HURT".

So, I fucked her twice and hit her with a brick.
Evil E is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:45 AM   #14
BV
wtf
 
BV's Avatar
 
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
Quote:
Originally Posted by Jace View Post
it is part of the control panel software and the software is zend encoded with no option to place them elsewhere
u can with a symbolic link of that directory
BV is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:52 AM   #15
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by BV View Post
u can with a symbolic link of that directory
no, i can't...I wish I could though

it HAS to be the way I am saying

I need something in htaccess that blocks EVERYONE out of that domain except our 2 ip's, but allows external sites to access the images in domain.com/cp/images/
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 01:55 AM   #16
dissipate
The Dirty Frenchman
 
dissipate's Avatar
 
Industry Role:
Join Date: Nov 2005
Location: Lost Angeles
Posts: 8,904
Hire a midget to protect it.
dissipate is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:00 AM   #17
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Code:
SetEnvIf Request_URI "\.gif$" imaginer
SetEnvIf Request_URI "\.jpg$" imaginer


Order deny,allow
Allow from env=imaginer
Allow from 71.254.148.228
Deny from all
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:01 AM   #18
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
You can add your own image types and IP's...

And send a hooker to my door.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:02 AM   #19
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by V_RocKs View Post
Code:
SetEnvIf Request_URI "\.gif$" imaginer
SetEnvIf Request_URI "\.jpg$" imaginer


Order deny,allow
Allow from env=imaginer
Allow from 71.254.148.228
Deny from all
trying it now

will you take a midget hooker?
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:04 AM   #20
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Or leave my IP in it so I can hax0r your shit for you...
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:05 AM   #21
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Quote:
Originally Posted by Jace View Post
trying it now

will you take a midget hooker?
No, but I will take a midget Doberman Pinscher.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:06 AM   #22
darksoul
Confirmed User
 
darksoul's Avatar
 
Join Date: Apr 2002
Location: /root/
Posts: 4,997
Code:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite1.com.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite2.com.*$ [NC]
RewriteRule .*\.(gif|jpg|png) - [F]

RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !.*\(gif|jpg|png) [NC]
RewriteCond %{REMOTE_ADDR} !^127.126.125.1$ [OR]
RewriteCond %{REMOTE_ADDR} !^122.122.122.12$ 
RewriteRule .* - [F]
I haven't tested it but should be close to the working version
__________________
1337 5y54|)m1n: 157717888
BM-2cUBw4B2fgiYAfjkE7JvWaJMiUXD96n9tN
Cambooth
darksoul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:08 AM   #23
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by V_RocKs View Post
Code:
SetEnvIf Request_URI "\.gif$" imaginer
SetEnvIf Request_URI "\.jpg$" imaginer


Order deny,allow
Allow from env=imaginer
Allow from 71.254.148.228
Deny from all
WORKED!!!!

thanks so much man, I owe ya one
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:11 AM   #24
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Now one thing you MIGHT have a problem with is if someone knows what you set the environment variable to, they can just set it themselves in the request... Which is why darksoul did his the correct way...

I just don't know that shit that well...
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:14 AM   #25
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Of course if they know the word you chose, they already have enough access to fuck you over...
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:21 AM   #26
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
Quote:
Originally Posted by V_RocKs View Post
Of course if they know the word you chose, they already have enough access to fuck you over...
i can just change that word to something else? "imaginer"
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:58 AM   #27
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
ImagineThat.... ;)
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 12:23 PM   #28
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Be aware that the crackers can and probably will at some point just spoof the referer
with a bit of JavaScript. Checking the referer will stop the casual user who doesn't
know anything, but it's not any kind of real security.

I know you said you can't do this, but I bet you can, so I'd take another look at what
other people suggested.
first symlink domain.com/cp/images/ to domain.com/public/images/ or better eachsite.com/members/images/
then protect domain.com/cp/
then search and replace the links from domain.com/cp/images/ to just /members/images/

I can't think of any possible scenario where a symlink wouldn't do the job.
The only thing I can think of is you had a $15 / month hosting account with no shell
access and and no customer support, making it hard to actually create the symlink.
Somehow I don't think that what you have, though. Still even then it takes 45 seconds
to write a script that creates the symlink.

If you symlink from each members' site it also has the enormous advantage of avoiding
all kinds of other problems you are going to have down the road if the URLs used for the
pics don't match their logical locations, ie. as part of each site.

If you can;t use a symlink to another domain or at least another directory I'm really
currious why that could possibly be. I'm also curious about what kind of POS CMS
you bought that caused all these problems.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids

Last edited by raymor; 07-13-2007 at 12:25 PM..
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 12:53 PM   #29
darksoul
Confirmed User
 
darksoul's Avatar
 
Join Date: Apr 2002
Location: /root/
Posts: 4,997
Quote:
Originally Posted by raymor View Post
2much2quote
you would've spared yourself the shame if you read/understood the thread.

The referer is checked only if the file type is an image for anything else
the access is allowed only from two ips.
they can spoof all they want.
__________________
1337 5y54|)m1n: 157717888
BM-2cUBw4B2fgiYAfjkE7JvWaJMiUXD96n9tN
Cambooth
darksoul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 02:07 PM   #30
munki
Do Fun Shit.
 
munki's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: OC
Posts: 13,393
The answer is 42
__________________

I have the simplest tastes. I am always satisfied with the best.” -Oscar Wilde
munki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-13-2007, 03:55 PM   #31
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
Quote:
Originally Posted by raymor View Post
Be aware that the crackers can and probably will at some point just spoof the referer
with a bit of JavaScript. Checking the referer will stop the casual user who doesn't
know anything, but it's not any kind of real security.

I know you said you can't do this, but I bet you can, so I'd take another look at what
other people suggested.
first symlink domain.com/cp/images/ to domain.com/public/images/ or better eachsite.com/members/images/
then protect domain.com/cp/
then search and replace the links from domain.com/cp/images/ to just /members/images/

I can't think of any possible scenario where a symlink wouldn't do the job.
The only thing I can think of is you had a $15 / month hosting account with no shell
access and and no customer support, making it hard to actually create the symlink.
Somehow I don't think that what you have, though. Still even then it takes 45 seconds
to write a script that creates the symlink.

If you symlink from each members' site it also has the enormous advantage of avoiding
all kinds of other problems you are going to have down the road if the URLs used for the
pics don't match their logical locations, ie. as part of each site.

If you can;t use a symlink to another domain or at least another directory I'm really
currious why that could possibly be. I'm also curious about what kind of POS CMS
you bought that caused all these problems.
You = Tool...

The referrer is NEVER checked... The requested URI is... You can't spoof that or the spoof is what you are asking for... Kind of like asking for coke and getting a coke... But if you spoof and ask for pepsi, well fine then, you get a pepsi (if it isn't denied to your IP address)...
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2007, 02:55 PM   #32
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Quote:
Originally Posted by V_RocKs View Post
You = Tool...

The referrer is NEVER checked... The requested URI is.
You = can't read. Or do you think that the three lines that say "HTTP_REFERER" are
checking soemthing other than the referer?

Quote:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite1.com.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite2.com.*$ [NC]
RewriteRule .*\.(gif|jpg|png) - [F]
Be careful ridiculing the guys who invented this shit, you are likely to make a fool of yourslf.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2007, 02:56 PM   #33
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Quote:
Originally Posted by V_RocKs View Post
You = Tool...

The referrer is NEVER checked... The requested URI is.
You = can't read. Or do you think that the three lines that say "HTTP_REFERER" are
checking something other than the referer?

Quote:
RewriteEngine On
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite1.com.*$ [NC,OR]
RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite2.com.*$ [NC]
RewriteRule .*\.(gif|jpg|png) - [F]
Be careful ridiculing the guys who invented this shit, you are likely to make a fool of yourself.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2007, 03:35 PM   #34
Jace
FBOP Class Of 2013
 
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
jesus you all

this is on a domain that is not public, not searched, not indexed, etc...it is a domain that ONLY has this control panel

and it isn't even in a typical folder, it is in something like domain.com/beegdjmf

so, what was brought up first, was perfect, my tech at nationalnet even said so ;)
Jace is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2007, 04:40 PM   #35
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Quote:
Originally Posted by darksoul View Post
you would've spared yourself the shame if you read/understood the thread.

The referer is checked only if the file type is an image for anything else
the access is allowed only from two ips.
they can spoof all they want.
So you don't mind if I hotlink all of your images? Thanks!
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-17-2007, 05:47 PM   #36
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,386
BTW http://www.htaccesstools.com/ is a great resource for almost every .htaccess-related task. Must be bookmarked by everyone IMHO.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.