SpikedRocker Posted January 26, 2016 Content Count: 6242 Joined: 04/13/08 Status: Offline Share Posted January 26, 2016 I decided a new thread was necessary to leave the older thread go as we are moving forward beyond the problem that got presented to us. You'll notice anything done before we turned everything off is still there and works. What will and has changed is all posts, PM's, profile messages and signatures from here on out. We've built a whitelist system that will allow you to use the IMG tag and if the domain is in our whitelist system, the image will show up. If the domain is not in the system, it will only display a link. Any images displayed like this are subject to moderators deleting the image and the post all together if we deem it necessary. That is the inherent problem with the type of exploit that was presented to us. We will not be able to fully stop it, really no bit of security measures we implement will stop it 100%. What we are doing is simply giving our users the upper hand. If someone tries to use the exploit, the only way it will work is if you click the link of the image they tried to put on our site. At that point, its your fault more than ours and sorry, but we aren't your babysitters. What we have done is made sure that unsuspecting users won't walk into a trap, they'll do that on their own if they click on it. Which is good internet security advice anyway. This exploit has been known for years apparently (new to myself and many of the other higher ups) as it is mearly used innocently enough to monitor traffic viewing files. It's role in a non-malicious way, is a good way to prove someone would be using/accessing specific files, possibly stealing them. However, in this nature, some people have found this is a pretty simple way to be used maliciously and use it to attack specific targets. So moving on with the details you'll need. Here is the current list of domains we have whitelisted: imgur.com photobucket.com inara.cz flicker.com facebook.com deviantart.com tinypic.com steamusercontent.com fbcdn.net steamsignature.com imageshack.us screencast.com rocketleaguestats.com puu.sh gyazo.com gfycat.com tumbler.com cubeupload.com We will look to add more to the list in the future, but we feel this is a good start and covers most popular things. If you need something more specific, message myself or a BD about it. Avatars are also back up too! 39 Link to comment
XeNo Posted January 26, 2016 Content Count: 6466 Joined: 07/22/08 Status: Offline Share Posted January 26, 2016 Huge thanks to @SpikedRocker @Liam Brown @Revenga for all the work they put into fixing up the images and taking care of the potential problem we might have had. 1 Link to comment
Wawa Posted January 26, 2016 Content Count: 3740 Joined: 05/21/12 Status: Offline Share Posted January 26, 2016 Thank you @SpikedRocker @Liam Brown @Revenga!!!! Link to comment
Metal Posted January 26, 2016 Content Count: 11727 Joined: 09/17/08 Status: Offline Share Posted January 26, 2016 Thanks all. Im sure it took a while to get this fixed. Once again. Thank you Link to comment
Prez Posted January 26, 2016 Content Count: 8758 Joined: 07/27/09 Status: Offline Share Posted January 26, 2016 Great work guys as always. Link to comment
Mandeemoo007 Posted January 26, 2016 Content Count: 1459 Joined: 01/07/14 Status: Offline Share Posted January 26, 2016 Thanks for the hard work guys! Link to comment
michellec Posted January 26, 2016 Content Count: 1546 Joined: 06/23/15 Status: Offline Share Posted January 26, 2016 Thank you guysss!! Link to comment
support my admin app Posted January 26, 2016 Content Count: 570 Joined: 11/27/15 Status: Offline Share Posted January 26, 2016 Thanks everybody Link to comment
xDoodles Posted January 26, 2016 Content Count: 1289 Joined: 04/29/09 Status: Offline Share Posted January 26, 2016 Danks Dad @SpikedRocker Link to comment
delirium Posted January 26, 2016 Content Count: 5382 Joined: 03/10/09 Status: Offline Share Posted January 26, 2016 Just a note, it's tumblr not tumbler Link to comment
Recommended Posts
Reply to Thread
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now