Quote:
readfile("../protected/myfile.zip");

Just make sure the "protected" subdirectory can't be directly reached from the web, and this should be the right answer.