To make my posting a bit clearer, yes I do want to hide the files true source from the client. The files are ZIP files. Basically it's trying to keep people from linking directly my files. I don't think that I need the extra security of session ID's, just a simple referrer check would probably suffice to keep my files from being linked all over the web. If you want to see what I am doing currently - peek at http://www.clan-originalsin.com/files/cgi-bin/files/os-files.pl?ViewStart=0&ViewCat=4&B1=View