RE: FN-FORUM: Paid for file downloads / streaming
date posted 1st December 2003 16:29
David Eckersall:
> yup, you supply it a valid URL, however using the response.redirect in
> the asp means its location is 'cloaked' and you can do any security
> testing before passing it over.
Barely cloaked. Once someone (anyone!) has successfully logged on, the
server sends them a 302 HTTP response with *the actual URL to the video*. So
they can bookmark it, distribute it, etc.
Security through obscurity doesn't work.
- Nick Grimshaw
{ if you're not part of the solution, you're part of the precipitate. }