Quote:
Originally Posted by Glorfindel
Cool
|
OK, C007 - -
The secrets revealed, at least enough to see how the site publishes files to the general public.
I still need to make time (maybe this weekend) to scrub the site of references to the prior (commercial) client.
But as a trial example:
- - - -
The proposed "invitation only" site has a main landing page, a twobob original, behind an authorization panel.
Behind the landing page, the site resources are provided by four different applications.
The menu bar at the top of the landing page represents those four sections.
The links orbiting the rolling rock are just additional links into various sections of the four main applications.
If you can catch one, you can try it.
Each of the four different applications requires a username/password to gain access.
I.E: None of them share the landing page's username/password.
Domain:
https://gunshi.org
Landing page user: MR.Secret
Landing page password: KT2PW2KV (you should be able to remember that, its the topic)
All that currently gets you is a chance to see the fancy landing page.
Even though you can not access the "Files" section of the site;
The filer can be set to publish files without access to the filer application itself.
(Although you have to get past the above privacy panel at least once per day.)
As in:
https://gunshi.org/pyd/data/public/8df81d.php
Password: MR.Secret
Published for only the next three days.
No limits on the number of downloads, just please don't beat my server to death.

Its a picture of my dogs, just as a working example.
All of the above only works over https, if you try http, the server will correct you.
One other note -
The above is a publicly posted download link, but this filer can also send out (e-mail) "invitation to download" messages which only work for the recipient.