# Preventing hotlinking of RTMP

**URL:** <https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482>\
**Category:** Wowza Streaming Engine\
**Created:** [October 28, 2013, 4:18pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482 "2013-10-28T16:18:00Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 4:18pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/1 "2013-10-28T16:18:00Z")

</div>

I have gone through the tutorial

[https://www.wowza.com/docs/how-to-combat-hotlinking-your-adobe-flash-swf-file](https://www.wowza.com/docs/how-to-combat-hotlinking-your-adobe-flash-swf-file)

But still i can access my stream from any domain name. I have some doubts regarding the addition of the module. I have extracted and copied /lib/wms-plugin-collection.jar from the package to the Wowza /lib folder. Where the other files are to be extracted?

In the Application.xml , Does the following line denotes the path?

```auto
<class>com.wowza.wms.plugin.collection.module.ModuleHotlinkDenial</Class>
 

```

Please do guide me. I am new to Wowza and started learning a week ago.

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [October 28, 2013, 11:25am UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/2 "2013-10-28T11:25:41Z")

</div>

Hi,

Have you added the Module and Properties to the Application.xml file?

After adding the files to the lib directory, Wowza will need to be restarted.

Add this Module last in the Modules section of your Application.xml

```auto
<Module>
	<Name>Hotlink Denial</Name>
	<Description>Hotlink Denial Module</Description>
	<Class>com.wowza.wms.plugin.collection.module.ModuleHotlinkDenial</Class>
</Module>

```

Add this Property section to the Properties section below the Modules in the Application.xml

```auto
<Property>
	<Name>domainLock</Name>
	<Value>localhost,mysite.com</Value>
</Property>
<Property>
	<Name>AllowEncoder</Name>
	<Value>Wirecast</Value> <!--FM, Wirecast-->
</Property>

```

After restarting Wowza are you able to play the RTMP stream from another site?

Jason

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 28, 2013, 1:23pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/3 "2013-10-28T13:23:41Z")

</div>

> still i can access my stream from any domain name.

What do you mean exactly? The hotlinkdenial helps prevent others from hotlinking your player’s swf file. It does not prevent anyone from using your RTMP url in their player.

Take a look at [Security Overview](https://www.wowza.com/docs/media-security-overview) guide. You probably want to use SecureToken.

Richard

---

<div class="post-metadata">

**Author:** ![Richard\_Lanham](https://avatars.discourse-cdn.com/v4/letter/r/c68b51/32.png) [@Richard\_Lanham](https://community.wowza.com/u/Richard_Lanham)\
**Post date:** [October 28, 2013, 1:39pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/4 "2013-10-28T13:39:46Z")

</div>

If your clients are all RTMP players and you are doing vod streaming, a full security suite includes SecureToken, RTMPE or RTMPS, HotLinkDenial and hotlink denial .htaccess rules.

If you are doing live streaming from a RTMP encoder, you would also use ModuleRTMPAuthenticate, which includes SecureToken.

Richard

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [October 28, 2013, 12:18pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/5 "2013-10-28T12:18:05Z")

</div>

Hi,

When you have added the Wowza Modules collection (wms-plugin-collection.jar) to the [Wowza-Install]/lib directory and added the Properties already mentioned then restarted Wowza, you will then be restricting the playback to the site configured by the domainLock Property. In the example Properties above, the website you want the stream to play from is called [mysite.com](http://mysite.com) and you will be allowing Wirecast encoders to publish to the application.

The code is provided for adjusting the Module should you choose to but is not needed other than for this purpose.

Can you post the Application.xml in the thread for me?

Thanks

Jason

\*Corrected typing error from [Wowza-Install]/bin to [Wowza-Install]/lib.

---

<div class="post-metadata">

**Author:** ![Jason\_Hilton](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/jason_hilton/32/437_2.png) [@Jason\_Hilton](https://community.wowza.com/u/Jason_Hilton)\
**Post date:** [October 28, 2013, 3:43pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/6 "2013-10-28T15:43:43Z")

</div>

Hi,

Also if you have “localhost” in the domainLock Property then any requests from the players on the same server as Wowza will be allowed.

```auto
<Property>
	<Name>domainLock</Name>
	<Value>localhost,mysite.com</Value>
</Property>

```

Jason

---

<div class="post-metadata">

**Author:** ![Matt\_Young](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/matt_young/32/389_2.png) [@Matt\_Young](https://community.wowza.com/u/Matt_Young)\
**Post date:** [October 28, 2013, 7:45am UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/7 "2013-10-28T07:45:54Z")

</div>

Try placing the Hotlink denial module last in the modules list. Also, to clarify, you’ll want to put the jar file in the [install-dir]/lib folder. If you have further issues run it in DEBUG mode and you should see each module load for the given application.

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 5:18pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/8 "2013-10-28T17:18:07Z")

</div>

I have tried this. But Still i can play my stream from another site. I have extracted the .java files to /usr/local/WowzaMediaServer/src/com/wowza/wms/plugin/collection/module/

Is this path correct? What is the role of Wirecast in the code?

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 5:53pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/9 "2013-10-28T17:53:24Z")

</div>

true

default

${com.wowza.wms.context.VHostConfigHome}/content

${com.wowza.wms.context.VHostConfigHome}/keys

${SourceStreamName}.xml,transrate.xml

${com.wowza.wms.context.VHostConfigHome}/transcoder/profiles

${com.wowza.wms.context.VHostConfigHome}/transcoder/templates

0

${com.wowza.wms.context.VHostConfigHome}/dvr

append

vodcaptionprovidermp4\_3gpp

cupertinostreaming,smoothstreaming,sanjosestreaming

-1

\*

\*

\*

\*

digest

none

senderreport

12000

75

90000

0

0.0.0.0

127.0.0.1

\*

interleave

Hotlink Denial

Hotlink Denial Module

com.wowza.wms.plugin.collection.module.ModuleHotlinkDenial

base

Base

com.wowza.wms.module.ModuleCore

logging

Client Logging

com.wowza.wms.module.ModuleClientLogging

flvplayback

FLVPlayback

com.wowza.wms.module.ModuleFLVPlayback

domainLock

localhost,[stream4life.com](http://stream4life.com)

AllowEncoder

Wirecast

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 6:01pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/10 "2013-10-28T18:01:22Z")

</div>

In the Tutorial, it is instructed to copy /lib/wms-plugin-collection.jar from the package to the Wowza /lib folder. But you said to copy it to [Wowza-Install]/bin directory . Anyways i tried both and nothing worked ☹ . Can i check the currently loaded modules of Wowza using some command?

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 6:28pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/11 "2013-10-28T18:28:40Z")

</div>

Not working ☹ ☹

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 28, 2013, 7:07pm UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/12 "2013-10-28T19:07:40Z")

</div>

> What do you mean exactly? The hotlinkdenial helps prevent others from hotlinking your player’s swf file. It does not prevent anyone from using your RTMP url in their player.
> 
> Take a look at [Security Overview](https://www.wowza.com/docs/media-security-overview) guide. You probably want to use SecureToken.
> 
> Richard

I tried the default wowza player in another browser and played the rtmp stream. Is nt it called as hotlink?

---

<div class="post-metadata">

**Author:** ![Stream\_4life](https://avatars.discourse-cdn.com/v4/letter/s/97f17d/32.png) [@Stream\_4life](https://community.wowza.com/u/Stream_4life)\
**Post date:** [October 29, 2013, 9:42am UTC](https://community.wowza.com/t/preventing-hotlinking-of-rtmp/41482/13 "2013-10-29T09:42:55Z")

</div>

Thanks all 🙂
