ok, copy and paste the following into you download.php file:
<?php
/**********************************
FileDownload (v2.0beta)
Created By: Kyle Jaebker
Last Modified: 10/15/2006
download.php - used to download file and track number of downloads
**********************************/
$incomingParams = base64_decode($_GET['dwn']);
if (!$incomingParams) {
echo 'Invalid parameters';
return;
}
list($dwnParams['file'],$dwnParams['incFileSize'],$dwnParams['size'],$dwnParams['dwnCount'],$dwnParams['useDb']) = explode('||',$incomingParams);
if (substr_count($dwnParams['file'], '..') > 0 or substr($dwnParams['file'], 0, 1) == '/') {
echo 'Invalid Filename';
return;
}
$dwnParams['countfile'] = $dwnParams['file'];
$dwnParams['file'] = '../../../' . $dwnParams['file'];
if (strstr($dwnParams['file'], 'manager') || strstr($dwnParams['file'], 'config.inc.php')) die();
$fileName = substr($dwnParams['file'],strrpos($dwnParams['file'],'/')+1);
if ( !file_exists($dwnParams['file']) ) {
echo 'File not found: ' . $fileName;
return;
}
$ext = explode('.', $fileName);
if ( sizeof($ext) < 2 ) {
echo 'Invalid filename: should have extension';
return;
}
$countPath = 'filecount.txt';
if ($dwnParams['dwnCount']) {
if ($dwnParams['useDb']) {
include_once '../../../manager/includes/config.inc.php';
include_once 'data.db.class.inc.php';
$fdData = new FdDataDb($database_server,$dbase,$database_user,$database_password,$table_prefix);
$fdData->connect();
$fdData->updateCount($dwnParams['countfile']);
$fdData->disconnect();
} else {
if(!$handle = fopen($countPath,'r+')) {
return 'file open failed: '.$countPath;
} else {
$i = 0;
// Get the files already counted
while ((list($fname,$count) = fgetcsv($handle, 1000)) !== FALSE) {
$files[$i]['name'] = $fname;
$files[$i]['count'] = $count;
$i++;
}
$fileInTxt = 0;
// Check if current file has been counted
foreach ( array_keys($files) as $key ) {
$myFile =& $files[$key];
if ($myFile['name'] == $dwnParams['countfile']) {
$myFile['count']++;
$fileInTxt = 1;
break;
}
}
fclose($handle);
// If file has not been counted add it to the array
if (!$fileInTxt) {
$i++;
$files[$i]['name'] = $dwnParams['countfile'];
$files[$i]['count'] = 1;
}
// ReOutput the count file
$handle = fopen($countPath,'w');
foreach ( $files as $file ) {
$str = $file['name'] . ',' . $file['count'] . '\r\n';
fwrite($handle, $str);
}
fclose($handle);
}
}
}
if (preg_match('#Opera(/| )([0-9].[0-9]{1,2})#', getenv('HTTP_USER_AGENT')) or
preg_match('#MSIE ([0-9].[0-9]{1,2})#', getenv('HTTP_USER_AGENT'))) {
$exeType = 'application/octetstream';
} else {
$exeType = 'application/octet-stream';
}
$extension = substr($fileName,strrpos($fileName,'.')+1);
switch($extension) {
case 'asf': $type = 'video/x-ms-asf'; break;
case 'avi': $type = 'video/x-msvideo'; break;
case 'bin': $type = 'application/octet-stream'; break;
case 'bmp': $type = 'image/bmp'; break;
case 'cgi': $type = 'magnus-internal/cgi'; break;
case 'css': $type = 'text/css'; break;
case 'dcr': $type = 'application/x-director'; break;
case 'dxr': $type = 'application/x-director'; break;
case 'dll': $type = 'application/octet-stream'; break;
case 'doc': $type = 'application/msword'; break;
case 'exe': $type = $exeType; break;
case 'gif': $type = 'image/gif'; break;
case 'gtar': $type = 'application/x-gtar'; break;
case 'gz': $type = 'application/gzip'; break;
case 'htm': $type = 'text/html'; break;
case 'html': $type = 'text/html'; break;
case 'iso': $type = 'application/octet-stream'; break;
case 'jar': $type = 'application/java-archive'; break;
case 'java': $type = 'text/x-java-source'; break;
case 'jnlp': $type = 'application/x-java-jnlp-file'; break;
case 'js': $type = 'application/x-javascript'; break;
case 'jpg': $type = 'image/jpg'; break;
case 'jpe': $type = 'image/jpg'; break;
case 'jpeg': $type = 'image/jpg'; break;
case 'lzh': $type = 'application/octet-stream'; break;
case 'mdb': $type = 'application/mdb'; break;
case 'mid': $type = 'audio/x-midi'; break;
case 'midi': $type = 'audio/x-midi'; break;
case 'mov': $type = 'video/quicktime'; break;
case 'mp2': $type = 'audio/x-mpeg'; break;
case 'mp3': $type = 'audio/mpeg'; break;
case 'mpg': $type = 'video/mpeg'; break;
case 'mpe': $type = 'video/mpeg'; break;
case 'mpeg': $type = 'video/mpeg'; break;
case 'pdf': $type = 'application/pdf'; break;
case 'php': $type = 'application/x-httpd-php'; break;
case 'php3': $type = 'application/x-httpd-php3'; break;
case 'php4': $type = 'application/x-httpd-php'; break;
case 'png': $type = 'image/png'; break;
case 'ppt': $type = 'application/mspowerpoint'; break;
case 'qt': $type = 'video/quicktime'; break;
case 'qti': $type = 'image/x-quicktime'; break;
case 'rar': $type = 'encoding/x-compress'; break;
case 'ra': $type = 'audio/x-pn-realaudio'; break;
case 'rm': $type = 'audio/x-pn-realaudio'; break;
case 'ram': $type = 'audio/x-pn-realaudio'; break;
case 'rtf': $type = 'application/rtf'; break;
case 'swa': $type = 'application/x-director'; break;
case 'swf': $type = 'application/x-shockwave-flash';break;
case 'tar': $type = 'application/x-tar'; break;
case 'tgz': $type = 'application/gzip'; break;
case 'tif': $type = 'image/tiff'; break;
case 'tiff': $type = 'image/tiff'; break;
case 'torrent': $type = 'application/x-bittorrent'; break;
case 'txt': $type = 'text/plain'; break;
case 'wav': $type = 'audio/wav'; break;
case 'wma': $type = 'audio/x-ms-wma'; break;
case 'wmv': $type = 'video/x-ms-wmv'; break;
case 'xls': $type = 'application/xls'; break;
case 'xml': $type = 'application/xml'; break;
case '7z': $type = 'application/x-compress'; break;
case 'zip': $type = 'application/x-zip-compressed'; break;
default: $type = 'application/force-download'; break;
}
$fp = fopen($dwnParams['file'],'r');
$filedata = fread($fp,filesize($dwnParams['file']));
fclose($fp);
//Send the user their download
header('Pragma: private');
header('Expires: 0');
header('Cache-Control: private, must-revalidate, post-check=0, pre-check=0');
header('Content-Type: ' . $type);
header('Content-Disposition: attachment; filename="'.$fileName.'";');
header('Accept-Ranges: bytes');
header('Content-Transfer-Encoding: binary');
if ($dwnParams['incFileSize']) {
header('Content-Length: ' . $dwnParams['size']);
}
print $filedata;
?>