Graal Forums  

Go Back   Graal Forums > Graal V6 forums > Bug Report
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rating: Thread Rating: 4 votes, 5.00 average. Display Modes
  #1  
Old 04-10-2008, 02:03 PM
Eranian Eranian is offline
Registered User
Join Date: Apr 2008
Posts: 22
Eranian is on a distinguished road
Exclamation HTML abuse in PMs

Earlier today I received a few PMs with download links embedded in <img> HTML tags.

The links were to Linux ISOs which were about 4GB each, and Graal tried to automatically download the files when I opened the PM.

I'm concerned because somebody could use the same method to link to more malicious files, and Graal no longer has an option to disable HTML in PMs.
Reply With Quote
  #2  
Old 04-10-2008, 02:11 PM
TSAdmin TSAdmin is offline
Forum Moderator
TSAdmin's Avatar
Join Date: Aug 2006
Location: Australia
Posts: 1,980
TSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud of
I just heard about this, myself. Even if we had an option to "disable HTML" implemented, now, people who choose not to disable it would be still prone. It wasn't so fun even getting PMs of ACTUAL images, at times, when the image itself was bigger than the PM window. Maybe HTML tags such as IMG need to be entirely removed.
__________________
TSAdmin (Forum Moderator)
Welcome to the Official GraalOnline Forums! Where sharing an opinion may be seen as a declaration of war!
------------------------
· User Agreement · Code of Conduct · Forum Rules ·
· Graal Support · Administrative Contacts ·
Reply With Quote
  #3  
Old 04-10-2008, 02:35 PM
Eranian Eranian is offline
Registered User
Join Date: Apr 2008
Posts: 22
Eranian is on a distinguished road
I like images in HTMLs.

Lucas has been hosting a lot of cool events on Era making excellent use of images in PMs to describe the event and such.

ISO is technically an image format though, except it's an image of an executable so it's not really safe.

If there were some way to limit the img tags to gifs, pngs & jpgs, and maybe even a filesize or image dimensions limit, that'd be nice.
Reply With Quote
  #4  
Old 04-10-2008, 02:55 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Yes will add a filter to only allow local server files in img tags.
Reply With Quote
  #5  
Old 04-10-2008, 03:04 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
Quote:
Originally Posted by Stefan View Post
Yes will add a filter to only allow local server files in img tags.
Why would you want to link a local server file as an image in PM?
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #6  
Old 04-10-2008, 03:16 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Rufus View Post
Why would you want to link a local server file as an image in PM?
Basic html or announcing PMs included. We did that on Era last christmas, having a christmas picture somewhere in the file browser we linked to in the news gui. Its useful.

Stefan, I think you should limit external links to ones with no extension, .html, .htm and maybe .php or .phtml.


Edit: And images, of course :o!
Reply With Quote
  #7  
Old 04-10-2008, 03:38 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
Quote:
Originally Posted by Crow View Post
Basic html or announcing PMs included. We did that on Era last christmas, having a christmas picture somewhere in the file browser we linked to in the news gui. Its useful.
Useful for server staff maybe, but not for players who simply want to embed images into their private messages though.
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #8  
Old 04-10-2008, 03:57 PM
xXziroXx xXziroXx is offline
Malorian
xXziroXx's Avatar
Join Date: May 2004
Posts: 5,289
xXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant future
Afaik, ISO files will NOT execute on their own, ever. I dont know of any program that auto opens them when you download them, and as long as you dont open it, who cares. Just delete it.

And Stefan, making it so only local images can be displayed with IMG tags kinda defeats the purpose of it. How about making a serveroption for "trusted domains" that staff could alter? Sorta like...

trusteddomains=imageshack.com,photobucket.com,graa lonline.com

And so fourth. Just throwing it out there..
__________________
Follow my work on social media post-Graal:Updated august 2025.
Reply With Quote
  #9  
Old 04-10-2008, 04:12 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Rufus View Post
Useful for server staff maybe, but not for players who simply want to embed images into their private messages though.
True ;f
Reply With Quote
  #10  
Old 04-10-2008, 04:24 PM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
Haha Linux pride!

Anyhoo, perhaps just filter out remote files > 2mb (screw BMPs) and to .jpg, .gif and .png.
Reply With Quote
  #11  
Old 04-10-2008, 04:49 PM
DrakilorP2P DrakilorP2P is offline
Registered User
DrakilorP2P's Avatar
Join Date: Apr 2006
Posts: 755
DrakilorP2P is just really niceDrakilorP2P is just really nice
Quote:
Originally Posted by xXziroXx View Post
Afaik, ISO files will NOT execute on their own, ever.
As far as I know, ISO files aren't executable.

Quote:
Originally Posted by Eranian View Post
ISO is technically an image format though, except it's an image of an executable so it's not really safe.
And I'm pretty sure that the files in question are archive files complete with all files and filesystem metadata in order to represent an optical disc.

On the other hand, it's possible to append large files onto a jpg image and <img> tag them.
Reply With Quote
  #12  
Old 04-10-2008, 05:05 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
You know, PM windows could be so much better. Going a little off topic, but I think PM's would be much better if they used something like BB Code along side a WYSIWYG or standard editor. The current features are pretty hidden, and not everyone knows you can embed images, but why? There probably should be a smileys menu instead of relying on going to the forums, and there should be a list of features somewhere.

Hmm.. heres a quick example mockup..
Attached Thumbnails
Click image for larger version

Name:	pm_interface.gif
Views:	1906
Size:	64.8 KB
ID:	44350  
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #13  
Old 04-10-2008, 05:07 PM
Dan Dan is offline
Daniel
Join Date: Oct 2007
Posts: 383
Dan is an unknown quantity at this point
Send a message via MSN to Dan
Nice
__________________
Reply With Quote
  #14  
Old 04-10-2008, 05:50 PM
Tigairius Tigairius is offline
The Cat
Tigairius's Avatar
Join Date: Jan 2007
Location: Missouri, USA
Posts: 4,240
Tigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant future
Quote:
Originally Posted by Twinny View Post
Anyhoo, perhaps just filter out remote files > 2mb (screw BMPs) and to .jpg, .gif and .png.
I agree.
Quote:
Originally Posted by Rufus View Post
Hmm.. heres a quick example mockup..
I think the PM windows should look something like this.
__________________


“Shoot for the moon. Even if you miss, you'll land among the stars.”
Reply With Quote
  #15  
Old 04-10-2008, 05:50 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Would be interesting if someone could script that, may be for the start add some "<b>" tags and similar.

For filtering it will allow the npcserver to send any tags, but filter the PMs of players to not allow urls, only local server files.
Reply With Quote
  #16  
Old 04-10-2008, 09:32 PM
SolidSnake989 SolidSnake989 is offline
Teh Whatz?!
SolidSnake989's Avatar
Join Date: Nov 2007
Location: Up Raven's.
Posts: 374
SolidSnake989 is on a distinguished road
But... i'll miss the not straight pr0nz people send out in mass pms
__________________
Wow, good job wasting your time reading this.
Reply With Quote
  #17  
Old 04-16-2008, 12:41 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
I've added logs for img-tags, will add filters later.
Reply With Quote
  #18  
Old 04-19-2008, 12:54 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Update: it seems the img-tag it is almost always used for displaying event screenshots or similar. So it might be better to only filter out bad file extensions (only allow png, jpg etc.) and add a check in the next Graal version to not download big files.
Reply With Quote
  #19  
Old 04-19-2008, 01:12 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Stefan View Post
Update: it seems the img-tag it is almost always used for displaying event screenshots or similar. So it might be better to only filter out bad file extensions (only allow png, jpg etc.) and add a check in the next Graal version to not download big files.
Somewhat similar to what I said. Yep, would be cool.
Reply With Quote
  #20  
Old 04-21-2008, 04:19 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
The filter is now active, and sends an admin message if there is an illegal img-tag. I've also banned someone for 3 days for sending iso-links. If there are any problems with the filter then please tell me.
Reply With Quote
  #21  
Old 04-21-2008, 04:28 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
Quote:
Originally Posted by Stefan View Post
The filter is now active, and sends an admin message if there is an illegal img-tag. I've also banned someone for 3 days for sending iso-links. If there are any problems with the filter then please tell me.
I've just tested it with Crono and it doesn't seem to report to RC? It probably should, not sure.
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #22  
Old 04-21-2008, 06:11 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Quote:
Originally Posted by Rufus View Post
I've just tested it with Crono and it doesn't seem to report to RC? It probably should, not sure.
It's not logging to RC, its logging in a central log. Could also display it on normal RC chat if wanted.
Reply With Quote
  #23  
Old 04-21-2008, 06:18 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Stefan View Post
It's not logging to RC, its logging in a central log. Could also display it on normal RC chat if wanted.
Would be neat
Reply With Quote
  #24  
Old 04-11-2009, 07:52 PM
Luda Luda is offline
Registered User
Join Date: Aug 2005
Location: Canada
Posts: 2,071
Luda has much to be proud ofLuda has much to be proud ofLuda has much to be proud ofLuda has much to be proud ofLuda has much to be proud ofLuda has much to be proud of
Send a message via AIM to Luda
Quote:
Originally Posted by rufus View Post
you know, pm windows could be so much better. Going a little off topic, but i think pm's would be much better if they used something like bb code along side a wysiwyg or standard editor. The current features are pretty hidden, and not everyone knows you can embed images, but why? There probably should be a smileys menu instead of relying on going to the forums, and there should be a list of features somewhere.

Hmm.. Heres a quick example mockup..
bump
Reply With Quote
  #25  
Old 04-11-2009, 08:24 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Did anyone script something like that already ?
Reply With Quote
  #26  
Old 04-11-2009, 08:32 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
Quote:
Originally Posted by Stefan View Post
Did anyone script something like that already ?
There was one on Unholy Nation, but it was a little over the top with features and I don't think anyone actually used it because of that.
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #27  
Old 04-11-2009, 08:50 PM
Elizabeth Elizabeth is offline
a/s/l
Elizabeth's Avatar
Join Date: Jul 2006
Location: Canada
Posts: 5,018
Elizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud of
Send a message via AIM to Elizabeth
Quote:
Originally Posted by Rufus View Post
There was one on Unholy Nation, but it was a little over the top with features and I don't think anyone actually used it because of that.
funny, that system actually was abandoned. it was supposed to be like, the next big thing and draw people to the server, but it was shortly ditched. it was supposed to be like a live chat, where you could send youtube videos attached to the chat, and pictures, coloured fonts, etc. you could aslo upload a picture as your avatar. it's still on unholy dev.


it wasn't that great tbh.
__________________
<3
Reply With Quote
  #28  
Old 04-11-2009, 09:48 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Well but I mean is there some improved PM text editor?
Reply With Quote
  #29  
Old 04-11-2009, 09:54 PM
Rufus Rufus is offline
Registered User
Join Date: Jun 2004
Location: United Kingdom
Posts: 4,698
Rufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud ofRufus has much to be proud of
Quote:
Originally Posted by Stefan View Post
Well but I mean is there some improved PM text editor?
I don't think so.
__________________
Quote:
Originally Posted by Loriel View Post
Seriously, you have ****-all for content and you're not exactly pulling in new developer talent, angling for prestigious titles should be your last concern.
Reply With Quote
  #30  
Old 04-12-2009, 05:35 AM
WhiteDragon WhiteDragon is offline
Banned
Join Date: Feb 2007
Posts: 1,002
WhiteDragon is a splendid one to beholdWhiteDragon is a splendid one to beholdWhiteDragon is a splendid one to beholdWhiteDragon is a splendid one to beholdWhiteDragon is a splendid one to behold
Stefan, if you give us the name of the scripted PM window GUI objects we could probably do it ourselves.
Reply With Quote
  #31  
Old 04-12-2009, 05:41 AM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Quote:
Originally Posted by WhiteDragon View Post
Stefan, if you give us the name of the scripted PM window GUI objects we could probably do it ourselves.
I'm sure you could just loop through like this...

PHP Code:
for (temp.control GUIContainer.controls) {
  echo(
control.name SPC "(" control.objecttype()  @ ")");

__________________
Reply With Quote
  #32  
Old 04-12-2009, 06:38 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
The text of the scripted PM control is not accessible to scripts, so it would be better to try it with normal GuiMLTextEditCtrl and then later give me the code.
Reply With Quote
  #33  
Old 04-14-2009, 09:20 PM
_Zelph _Zelph is offline
Registered User
Join Date: Mar 2003
Posts: 78
_Zelph is on a distinguished road
Quote:
Originally Posted by Elizabeth View Post
funny, that system actually was abandoned. it was supposed to be like, the next big thing and draw people to the server, but it was shortly ditched. it was supposed to be like a live chat, where you could send youtube videos attached to the chat, and pictures, coloured fonts, etc. you could aslo upload a picture as your avatar. it's still on unholy dev.


it wasn't that great tbh.
Elizabeth, you're a weirdo.

The system was never abandoned. I'm just waiting for Stefan to get off his fat butt and release a public graal client that supports external windows

And the current version of GIM makes the old one look like utter crap. Your sentiment is understandable since the old one is the only version you've ever seen.

Here's a recent screenshot:

Reply With Quote
  #34  
Old 04-14-2009, 09:22 PM
Elizabeth Elizabeth is offline
a/s/l
Elizabeth's Avatar
Join Date: Jul 2006
Location: Canada
Posts: 5,018
Elizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud of
Send a message via AIM to Elizabeth
Quote:
Originally Posted by _Zelph View Post
Elizabeth, you're a weirdo.

The system was never abandoned. I'm just waiting for Stefan to get off his fat butt and release a public graal client that supports external windows

And the current version of GIM makes the old one look like utter crap. Your sentiment is understandable since the old one is the only version you've ever seen.

Here's a recent screenshot:

i lol'd. looks good, though.
__________________
<3
Reply With Quote
  #35  
Old 04-15-2009, 11:54 AM
Stephen Stephen is offline
Boom!
Stephen's Avatar
Join Date: May 2004
Location: San Francisco
Posts: 10,410
Stephen has much to be proud ofStephen has much to be proud ofStephen has much to be proud ofStephen has much to be proud ofStephen has much to be proud ofStephen has much to be proud of
Quote:
Originally Posted by Rufus View Post
Hmm.. heres a quick example mockup..
All that stuff is scripted now, so it should be possible to introduce a better system if I understand correctly.


The whole Graal GUI desperately needs a overhaul and some standards set so servers can also follow them in their own GUIs (settings, etc). Removes unnecessary learning curves and just makes the trivial things less tedious.
__________________
Reply With Quote
  #36  
Old 04-15-2009, 12:40 PM
Elizabeth Elizabeth is offline
a/s/l
Elizabeth's Avatar
Join Date: Jul 2006
Location: Canada
Posts: 5,018
Elizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud ofElizabeth has much to be proud of
Send a message via AIM to Elizabeth
i like the current playerlist, i'd rather have it than have people spamming servers up with their size 36 bolded underlined and italics rainbow coloured font. not to mention it's easier for people to mass pictures, masses are going to be spammed with them.
__________________
<3
Reply With Quote
  #37  
Old 04-17-2009, 11:24 AM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Well people can already do that right now, it's just requiring a little bit more effort
Reply With Quote
  #38  
Old 01-31-2010, 03:11 AM
scriptless scriptless is offline
Banned
Join Date: Dec 2008
Location: N-Pulse
Posts: 1,412
scriptless is a splendid one to beholdscriptless is a splendid one to beholdscriptless is a splendid one to beholdscriptless is a splendid one to behold
Hmm. Would be neat to actually filter images properly tho? ".jpg" does not mean the file is a picture at all. It just means the extension is .jpg and the computer then knows what application to use to execute/open/run it. You can make harmfull files and rename them to .jpg. So I think filtering just names would be bad, but filter the images correctly. Check headers or what not to verify them? plz.

Anyone know if JavaScript still works in pm's that was highly abusive and used to be used back in the day to scam the hell out of people on Graal Kingdoms. I had that happen to me with my brothers items many many years ago.

Now I am not saying, "OMG pm's epic fail". I am only saying just because no one has found a way to use an image file for abuse sich as the Gif, Tif, and other overflows that I do remember circulating around the internet years ago. But in the same sence, if you leave your wallet on the floor at walmart and no one steals it does it mean thats a safe place to store your money? Not at all, never assume nothing bad will happen (prevent it) before it happens. Great lesson of life to learn everyone.
Reply With Quote
  #39  
Old 01-31-2010, 03:47 AM
12171217 12171217 is offline
Banned
Join Date: Jan 2009
Posts: 453
12171217 has a spectacular aura about
If this topic wasn't so old and already pretty much remedied, I would praise your analogy.
Reply With Quote
  #40  
Old 01-31-2010, 03:54 AM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Would also be great if a limit was placed on animated smilies in PMs. I assume the text ': D' is just being replaced with the image code for when displaying PMs, so it should be easy to only display 10 or so smilies per PM. We had to block , , , , , , , and on Era because they were being massed out and crashing everyone's client when they opened them.
__________________
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 05:28 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.