UltraVNC
UltraVNC copied to clipboard
Dealing with SC's generated files online
When generating SC files to download, you get an actual link (rather than a data URI scheme).
This causes 2 issues:
- Those links are kept at https://support1.uvnc.com/SC/ which is a public accessible folder, so everyone can find your files.
- If you use a filename someone else already used (like just
helpdesk.exe), it overwrites their own download link. This means they'll download your link or you'll download theirs.
What I suggest is:
- Don't allow to see folders. This link states you use Apache so just turn Options Directive of
Indexesoff. - Force the filename to be unique (don't allow filenames that already exist in that folder).
- Clearly state the expiration time and preferably use JavaScript to make a dynamic countdown.
- Or just use the aforementioned data URI scheme to maintain full privacy.
Either way, can you state even just here how long before you delete our generated files? Looking at the current folder I would say 24 hours.
Should be:
The folder used to be hidden, but then people asked to open it to be able to find old generated files. ok, will block back folder listing
Each user should only see their own files then.
How long before each file is deleted?
@lwcorp: Very good remarks :)