Advanced search  

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Pages: [1]   Go Down

Author Topic: Image Path URL Easy to Hack ?  (Read 4930 times)

0 Members and 1 Guest are viewing this topic.

rostros

  • Coppermine novice
  • *
  • Offline Offline
  • Posts: 49
Image Path URL Easy to Hack ?
« on: September 13, 2004, 12:21:49 pm »

Im sure I have seen one of these related threads before but could not find it.

Anyways My CPG has members and I have it so only Registered Members can See Full Size Only, and Un-Registered Members can see the Thumbnail and Intermediate Photo, I have noticed that there is an Easy hack to see the Full Size image, once the intermediate photo is loaded, the Un registered user can right click and view the Photo URL Path e.g

                  http:yoursite.com/cpg/images/gallery/normal_image.jpg  

Then all they need to do is delete the Normal_ and they have the ability to view the full picture using a direct path, also this is a problem as image hotlinking to other sites is a big problem for me.

I have currently got a Javascript disabling the right click on images but I would like to be able to remove this as right click is a popular choice when looking at images.

Any Help would be great  :)
Logged

Casper

  • VIP
  • Coppermine addict
  • ***
  • Country: 00
  • Offline Offline
  • Gender: Male
  • Posts: 5231
Re: Image Path URL Easy to Hack ?
« Reply #1 on: September 13, 2004, 06:20:26 pm »

Logged
It has been a long time now since I did my little bit here, and have done no coding or any other such stuff since. I'm back to being a noob here

TyL

  • Coppermine newbie
  • Offline Offline
  • Posts: 17
Re: Image Path URL Easy to Hack ?
« Reply #2 on: September 21, 2004, 05:26:35 pm »

Ok but don't work on apache & windows :(
Logged

Tranz

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: 00
  • Offline Offline
  • Gender: Female
  • Posts: 6149
Re: Image Path URL Easy to Hack ?
« Reply #3 on: September 21, 2004, 05:34:16 pm »

I think that code just prevents hotlinking, but not direct access from the browser address bar.

Try this: http://forum.coppermine-gallery.net/index.php?topic=3021.msg45672#msg45672

But I don't know if it is specific to linux/unix.

@TyL: Also, since you have multiple questions, please specify what doesn't work and how it doesn't work.
Logged

Tarique Sani

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 2712
    • http://tariquesani.net
Re: Image Path URL Easy to Hack ?
« Reply #4 on: September 22, 2004, 06:48:58 am »

You can have an .htaccess file check for referer and see if it is displayimage.php of your site - basically the same principle as the prevention of hotlinking - AFAIK .htaccess will work just the same on Apache for windows as it does for *nix

But still my contention is if it is on the web it is stealable - may be you should really look at session based one time URL generation
Logged
SANIsoft PHP applications for E Biz
Pages: [1]   Go Up
 

Page created in 0.034 seconds with 20 queries.