Question about using a FTP server

Aerosys

Veteran
Veteran
Joined
Apr 23, 2019
Messages
351
Reaction score
325
First Language
german
Primarily Uses
RMMZ
Hey all,

I have a short question about having a FTP server. So when I want to upload (experimental, paywalled, beta..) files on my FTP server, and I put them into a directory with a long link eg. "root/hidden-files/ksjflösjföl</" do only people having the link have access to those files or are there any (dirty) tricks to read out all the directories from a server?
 

Andar

Veteran
Veteran
Joined
Mar 5, 2013
Messages
30,948
Reaction score
7,460
First Language
German
Primarily Uses
RMMV
if you haven't disabled htaccess for those folders, anyone can follow the directory structure as it will be displayed (including parent link and subfolder names) as soon as a valid foldername is entered.

to prevent this you either need to restrict access or place an index.html with an auto-redirect to the top on every folder that does not need to be accessed. Don't do this for the final folder that you want to be accessed of course.
 

Aerosys

Veteran
Veteran
Joined
Apr 23, 2019
Messages
351
Reaction score
325
First Language
german
Primarily Uses
RMMZ
if you haven't disabled htaccess for those folders, anyone can follow the directory structure as it will be displayed (including parent link and subfolder names) as soon as a valid foldername is entered.

to prevent this you either need to restrict access or place an index.html with an auto-redirect to the top on every folder that does not need to be accessed. Don't do this for the final folder that you want to be accessed of course.
Thanks for the detailed info.

But I'm not sure if we are talking about the same thing. My directory structure is never presented to the public and I don't use any index.html. So you can access this file http://downloads.aerosys.blog/MK_RandomGenerate_Dungeon.js but when you click here http://downloads.aerosys.blog/index.html or here http://downloads.aerosys.blog you see nothing.
 

Andar

Veteran
Veteran
Joined
Mar 5, 2013
Messages
30,948
Reaction score
7,460
First Language
German
Primarily Uses
RMMV
yes, we are talking about the same, see attached picture.

if ANY folder in your structure does not have a index.html and not a htaccess file restricting access, then that picture is what every browser will display - and you can see all available subfolders there.
if anyone makes even one successfull guess at what one of the first subfolders is like, they don't need to know the rest of the structure because they can follow it in any browser.

to prevent that you NEED either htaccess restrictions or an index.html in the folder, because only those will automatically be checked if there is no file listed in the adress.
index.png
 

Aerosys

Veteran
Veteran
Joined
Apr 23, 2019
Messages
351
Reaction score
325
First Language
german
Primarily Uses
RMMZ
Okay, so I tried to reproduce it, but I never get to see something that looks alike your screenshot. So I assume my provider already enables htaccess file restrictions or it is not a real FTP, but rather something that looks and feels alike.

Thanks for your explanation!


So if somebody still finds a way to browse through my files under the domain 2 posts above, please tell me :D
 

Andar

Veteran
Veteran
Joined
Mar 5, 2013
Messages
30,948
Reaction score
7,460
First Language
German
Primarily Uses
RMMV
So I assume my provider already enables htaccess file restrictions or it is not a real FTP,
then most likely your provider activates it - my screenshot is from Firefox, I just cut away the tool buttons and so on, no FTP involved at all. But I did manage my server manually without any CMS, and that folder is intentionally designed to let others download files.
 

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

Latest Threads

Latest Posts

Latest Profile Posts

I always told my DA fans how much I hate slot machines. They're fine in games as a risk-and-reward system. But when you're spending REAL MONEY in a Vegas casino to try and hit the jackpot (which very, very few people will), it can really hurt your budget. Gambling is a bad habit, and I don't like wasting my money on a slim chance. Go to Vegas for the experience, not the jackpot.
Took the kids to a corn maze. They gave us a map and had lights at certain points in the maze. Not overwhelming... or underwhelming... just... whelming.
Okay, vacuuming fruit flies out of the air is surprisingly effective.
Finally finished my menu redesign after like a month of coding! I hate designing menus... Good news though - I thought of a complete redesign for it now, so yay...
Still no scam calls all day... also I got a quick gig designing a mascot drawing for a small business, so I might actually make some green of my own after all. That would be a perfect job for me, since I love art and digital design.

Forum statistics

Threads
104,391
Messages
1,006,038
Members
135,920
Latest member
chelsandherself
Top