Prevent Hotlinking of Your Picture Files

Written by Bec on October 30, 2009 – 1:30 PM -

If you’re noticing a major increase in your bandwidth usage, you may have others hotlinking to your picture files, which is theft of your bandwidth and is called bandwidth leeching. A simple way to stop hotlinking is by adding this to your .htaccess file:

RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?mydomain.com/.*$ [NC]
RewriteRule \.(gif|jpg)$ – [F]

Replace mydomain.com with your actual domain name. With this code in place, your images will only display when the visitor is browsing http://mydomain.com. Images linked from other domains will appear as broken images.

If you’re feeling particularly nasty, you can even provide an alternative image to display on the hot linked pages — for example, an image that says “Stealing is Bad … visit http://mydomain.com to see the real picture that belongs here.” Use this code to accomplish that:

RewriteEngine on
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?mydomain.com/.*$ [NC]
RewriteRule \.(gif|jpg)$ http://www.mydomain.com/dontsteal.gif [R,L]

This time, replace mydomain.com with your domain name, and replace dontsteal.gif with the file name of the image you’ve created to discourage hot linking.

Be sure to upload your .htaccess in ASCII mode, and once it’s up there, chmod it to 644.


Tags: ,
Posted in Articles & Tutorials, Security Issues | No Comments »
RSS