Hacker News new | ask | show | jobs
by romland 1928 days ago
You say "All test files are deleted after 24 hours.", that implies to me that files people upload _could_ be downloaded too.

If that is the case, that is where you are vulnerable. Free hosting of a file at a trusted domain is worth something.

If people are not intended to be able to download their test files, check your logs, someone might have found a way around it.

That's the best I can think of.

1 comments

Yes you are correct they can download it too. After thinking about it for the last 4 hours that is all i can think off caused the problem. I have nothing which can be called deceptive text on any of my site otherwise.

I will probably delete files after 2 mins instead of 24 hours.

Another option is I ask for credit card details before I let them try the demo. This can get rid of letting anyone misusing the demo features.

Just as a point, I wouldn’t give you credit card details to try a demo. I don’t think many people would - hard enough to get people to give them for a trial, nevermind to try uploading a file.