![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
htaccess HELP!
I have a site/directory that I only want myself and my partner to be able to load up
I was going to use a deny all ip's but ours, but the issue is that we have other sites that pull images from this domain so, how can I restrict anyone but us two from that domain, but allow images to be pulled from ANY domain from there? |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
basically, the issues is, we have an important control panel on that domain, and I want only us to access that control panel...it is already password protected to get into the control panel....but I still want that extra level of htaccess control to only allow our ip's
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Join Date: Jul 2004
Location: Denmark ICQ: 7880009
Posts: 2,203
|
Ignore me. I misread your post
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Or... put the control panel in a directory like,
58ju4Tg and then restrict access in that directory. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
wtf
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
|
maybe do a symbolic link of the images dir or move the control panel to another dir
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Aug 2005
Location: Las Vegas, NV
Posts: 1,099
|
why can't you just store the images somewhere else?
__________________
Spunky Dollars | Need Content? Paysite Owners: Protect Your Members Area with Strongbox 361-574-229 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
What types of images?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
ie, just gif, jpg?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Apr 2005
Location: Lazyness is a lifestyle
Posts: 3,201
|
slkfjaldika;ie';1190-9
__________________
![]() A girl once told me "Give me 8 inches and make it HURT". So, I fucked her twice and hit her with a brick. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
wtf
Industry Role:
Join Date: Sep 2001
Location: Bikini State, FL USA
Posts: 10,914
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
no, i can't...I wish I could though
it HAS to be the way I am saying I need something in htaccess that blocks EVERYONE out of that domain except our 2 ip's, but allows external sites to access the images in domain.com/cp/images/ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
The Dirty Frenchman
Industry Role:
Join Date: Nov 2005
Location: Lost Angeles
Posts: 8,904
|
Hire a midget to protect it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Code:
SetEnvIf Request_URI "\.gif$" imaginer SetEnvIf Request_URI "\.jpg$" imaginer Order deny,allow Allow from env=imaginer Allow from 71.254.148.228 Deny from all |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
You can add your own image types and IP's...
And send a hooker to my door. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Or leave my IP in it so I can hax0r your shit for you...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
Code:
RewriteEngine On RewriteCond %{HTTP_REFERER} !^$ RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite1.com.*$ [NC,OR] RewriteCond %{HTTP_REFERER} !^http://(.*)?mysite2.com.*$ [NC] RewriteRule .*\.(gif|jpg|png) - [F] RewriteEngine On RewriteCond %{REQUEST_FILENAME} !.*\(gif|jpg|png) [NC] RewriteCond %{REMOTE_ADDR} !^127.126.125.1$ [OR] RewriteCond %{REMOTE_ADDR} !^122.122.122.12$ RewriteRule .* - [F] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Now one thing you MIGHT have a problem with is if someone knows what you set the environment variable to, they can just set it themselves in the request... Which is why darksoul did his the correct way...
I just don't know that shit that well... |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Of course if they know the word you chose, they already have enough access to fuck you over...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
ImagineThat.... ;)
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Be aware that the crackers can and probably will at some point just spoof the referer
with a bit of JavaScript. Checking the referer will stop the casual user who doesn't know anything, but it's not any kind of real security. I know you said you can't do this, but I bet you can, so I'd take another look at what other people suggested. first symlink domain.com/cp/images/ to domain.com/public/images/ or better eachsite.com/members/images/ then protect domain.com/cp/ then search and replace the links from domain.com/cp/images/ to just /members/images/ I can't think of any possible scenario where a symlink wouldn't do the job. The only thing I can think of is you had a $15 / month hosting account with no shell access and and no customer support, making it hard to actually create the symlink. Somehow I don't think that what you have, though. Still even then it takes 45 seconds to write a script that creates the symlink. If you symlink from each members' site it also has the enormous advantage of avoiding all kinds of other problems you are going to have down the road if the URLs used for the pics don't match their logical locations, ie. as part of each site. If you can;t use a symlink to another domain or at least another directory I'm really currious why that could possibly be. I'm also curious about what kind of POS CMS you bought that caused all these problems. ![]()
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Confirmed User
Join Date: Apr 2002
Location: /root/
Posts: 4,997
|
you would've spared yourself the shame if you read/understood the thread.
The referer is checked only if the file type is an image for anything else the access is allowed only from two ips. they can spoof all they want. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
Do Fun Shit.
Industry Role:
Join Date: Dec 2004
Location: OC
Posts: 13,393
|
The answer is 42
__________________
![]() “I have the simplest tastes. I am always satisfied with the best.” -Oscar Wilde |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 | |
Damn Right I Kiss Ass!
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,409
|
Quote:
The referrer is NEVER checked... The requested URI is... You can't spoof that or the spoof is what you are asking for... Kind of like asking for coke and getting a coke... But if you spoof and ask for pepsi, well fine then, you get a pepsi (if it isn't denied to your IP address)... |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 | ||
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Quote:
checking soemthing other than the referer? Quote:
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 | ||
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
Quote:
checking something other than the referer? Quote:
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
FBOP Class Of 2013
Industry Role:
Join Date: Jan 2004
Location: bumfuck, ky
Posts: 35,562
|
jesus you all
this is on a domain that is not public, not searched, not indexed, etc...it is a domain that ONLY has this control panel and it isn't even in a typical folder, it is in something like domain.com/beegdjmf so, what was brought up first, was perfect, my tech at nationalnet even said so ;) |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Confirmed User
Join Date: Oct 2002
Posts: 3,745
|
So you don't mind if I hotlink all of your images? Thanks!
__________________
For historical display only. This information is not current: support@bettercgi.com ICQ 7208627 Strongbox - The next generation in site security Throttlebox - The next generation in bandwidth control Clonebox - Backup and disaster recovery on steroids |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,386
|
BTW http://www.htaccesstools.com/ is a great resource for almost every .htaccess-related task. Must be bookmarked by everyone IMHO.
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |