Joined: Dec 02, 2006 Posts: 1364 Location: Texas, USA
Posted:
Mon Mar 26, 2007 8:20 pm
Well as I usually do I searched your forums BEFORE posting a question which 9 times out of 10 solves my problem/question. But only posts I found about this were older than dirt. I have "Enable remote avatars" set to "ON" and wonder if I should reconsider... This is
Only registered users can see links on this board! Get registered or login to the forums!
Quote:
This has been a known problem for a great deal of time. The fact is, webmasters should have that feature turned off for a variety of reasons, but the major reason being vulnerabilities.
Simply go to Forum Admin/General Configuration and disable "Enable remote avatars" to solve this problem.
If people want to have an avatar, they can pick one from the gallary or upload one. You shouldn't need to remote feed one in the first place.
I take it this feature has been secured some since these days, but is it still one of those features that is better left disabled? Is uploading an avatar less of a security risk than Enable remote avatars? I always thought allowing any sort of upload was the last thing you should allow...?
Also, if I disable this now, I assume any members' avatars that have been set in this manner wont work anymore...
Thanks in advance for your time
oh and btw I'm running latest RN distro and sentinel
Joined: Aug 28, 2003 Posts: 6373 Location: Vsetin, Czech Republic
Posted:
Tue Mar 27, 2007 9:30 am
Security in that area has been improved but why take the chance?
If any of my users want their own avatar I'm quite happy to upload it for them and set it up in their account. I do make regular back-ups but I can really do without the hassle of someone linking to something nasty
Joined: Aug 28, 2003 Posts: 6373 Location: Vsetin, Czech Republic
Posted:
Wed Mar 28, 2007 1:56 am
Turning off 'allow html' in the forum set up will help. I have never really used the signatures feature for images but I'm fairly sure you cannot actually 'upload' an image, instead it tends to be a remote link.
Again, this is vulnerable but you also have the added impact that linking to external content will usually slow your site down and in some cases when the image cannot be found, it can slow the site down quite badly. Make it a habit that wherever possible, your site only links to images that are uploaded to your hosting webspace.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum