Facebook  Twitter 

SMFHacks.com

+- +-

SMFHacks.com

+- User Information

Welcome, Guest.
Please login or register.
 
 
 
Forgot your password?

+- Forum Stats

Members
Total Members: 12347
Latest: JessielGonzalez2
New This Month: 11
New This Week: 1
New Today: 0
Stats
Total Posts: 39779
Total Topics: 7005
Most Online Today: 102
Most Online Ever: 2482
(April 09, 2011, 07:02:45 pm)
Users Online
Members: 0
Guests: 27
Total: 27

Author Topic: Bypass Download Limit Bug  (Read 3713 times)

0 Members and 1 Guest are viewing this topic.

Offline elbeer

  • Full Member
  • ***
  • Posts: 100
    • View Profile
Bypass Download Limit Bug
« on: March 15, 2015, 06:21:27 am »
This is quite a pain of a bug. If a user opens up a list of downloads e.g. from http://mydomain.com/index.php?action=downloads;cat=5

And say 10 downloads are listed. If they right click each page for the download and open them up in separate tabs they will have 10 pages open with 10 different downloads.

Even though I have a download limit per day set in admin - they can simply press download on each of the open tabs and gain access to each download bypassing any limits I have set.

I have locked down the template but there needs to be some sort of check from downloads2.php prior to releasing the download. e.g. on click of the link check the download count before going on to reveal the download.


Offline SMFHacks

  • Administrator
  • Hero Member
  • *****
  • Posts: 14903
    • View Profile
Re: Bypass Download Limit Bug
« Reply #1 on: March 18, 2015, 10:09:20 pm »
Quote

Even though I have a download limit per day set in admin - they can simply press download on each of the open tabs and gain access to each download bypassing any limits I have set.
I don't see how that is possible.... I looked at the code it calls the Downloads_DownloadFile file in Downloads2.php and that handles all the checks before the file can be downloaded.
Get your Forum Ranked! at https://www.forumrankings.net - find out how your forum compares with others!

Like What I do? Support me at https://www.patreon.com/vbgamer45/

Offline elbeer

  • Full Member
  • ***
  • Posts: 100
    • View Profile
Re: Bypass Download Limit Bug
« Reply #2 on: March 19, 2015, 03:17:04 am »
The checks are done when you open the download page. So if you open 20 download pages and dont actually download anything until all 20 tabs are open you can download as many files as you like.

Offline SMFHacks

  • Administrator
  • Hero Member
  • *****
  • Posts: 14903
    • View Profile
Re: Bypass Download Limit Bug
« Reply #3 on: March 19, 2015, 08:05:45 am »
But you shouldn't be able to download the files though... You might be able to open the pages to view download page but not actually download the files.
Get your Forum Ranked! at https://www.forumrankings.net - find out how your forum compares with others!

Like What I do? Support me at https://www.patreon.com/vbgamer45/

Offline elbeer

  • Full Member
  • ***
  • Posts: 100
    • View Profile
Re: Bypass Download Limit Bug
« Reply #4 on: March 23, 2015, 10:17:09 am »
But you can. If you open the download page without actually clicking download the link is rendered but is not counted. If you open up multiple pages where the links are rendered you can then download each file without checking the amount of downloads.

 

Related Topics

  Subject / Started by Replies Last post
3 Replies
4319 Views
Last post February 08, 2008, 01:39:16 am
by rtyug
1 Replies
3488 Views
Last post February 07, 2008, 09:59:50 pm
by rtyug
3 Replies
4686 Views
Last post May 19, 2008, 08:30:12 pm
by ApplianceJunk
3 Replies
1741 Views
Last post December 09, 2010, 10:43:34 am
by SMFHacks
4 Replies
2033 Views
Last post February 02, 2013, 11:42:07 am
by amwebby

+- Recent Topics

Update by SMFHacks
June 19, 2019, 10:58:25 am

About Comments Approval by ajac63
June 12, 2019, 07:48:52 pm

Pretty Urls extras by SMFHacks
June 06, 2019, 12:14:53 pm

About using chmod to secure files by ajac63
June 05, 2019, 04:02:28 am

Bulk upload image problem by SMFHacks
June 01, 2019, 07:24:00 pm

About Watermark Options by ajac63
May 30, 2019, 05:25:39 pm

Why PayPal only by ajac63
May 30, 2019, 04:20:47 pm

Seller ToU not showing by ajac63
May 29, 2019, 01:59:24 am

Not happy by ajac63
May 28, 2019, 06:37:58 pm

About Number of Images for Basic Ad by ajac63
May 26, 2019, 10:33:46 pm

Powered by EzPortal