Posts: 4,878
Threads: 162
Joined: Mar 2008
I have looked at the code that deals with avatar-uploading. Basically, it goes like this:
- Upload to LFE
- Let a user specify an image-file to upload it
- Transfer and store the file on the server (if necessary, replace the old one with the new)
- Perform a few calculations (especially image size so that it'll be displayed correctly all over the place and auto-resize / throw an error in case the dimensions are larger than acceptable)
- Update the respective entry in the database
- Use an external host
- Follow the link specified
- Because of security-reasons, PHP cannot get image-data from a non-local place. Hence, download it and run the same calculations as in local mode
- Update database-entry and delete the downloaded copy from the local server
You probably see the problem: either way requires write-permissions. The verification-process is, according to my understanding, impossible to do remotely. And even if there was a way, that'd require me to edit the PHP-files. Which I can't. WHICH NOBODY CAN! TEH APOCALYPSE!!
Silverthorn / Blue Phoenix
~ Breaking LFE since 2008 ~
"Freeze, you're under vrest!" - Mark, probably.
» Gallery | » Sprites | » DeviantArt
Posts: 2,340
Threads: 78
Joined: Mar 2008
Okay now that the 403 is getting more frequent and I suspect it is still some ddos disguised as a crawler I asked my own webhost how they deal with this kind of stuff.
First of all they have scripts running that auto ban IPs upon huge request amounts. I can only hope LFEs webhost has that too or else you should really consider paying someone else for this in case you can. If you somehow cannot get out of the contract or anything we seriously need to set up our own scripts to catch this stuff. Cause it's a real shame if you have to pay for nothing.
Posts: 496
Threads: 21
Joined: Apr 2013
LFE needs a better antivirus system in think so that it cannot be hacked
Credits to PF for my Current Avatar, and Possibly my Rep Char F
Interested in Gaming? Check out my channel, its going to be updated soon.
You're just dying if you're living and thinking about a betrayal, revive yourself.
Think about that one person that has trusted you forever, not the thousand people that have betrayed you.
Thanks given by:
Posts: 2,591
Threads: 259
Joined: Feb 2008
it doesnt need a better antivirus, it needs a softwareupdate. Problem is neither BluePhoenix or me got the time to rebuild the mainsite.
Everybody with suggestions for that problem is welcome.
www.lf-empire.de
Once I had a fortune, it said: "Leave now. Life is short. Time is luck" Don't dream your life, live your dream!
Thanks given by:
Posts: 2,340
Threads: 78
Joined: Mar 2008
Host the mainsite elsewhere so the forum doesn't go down because of it.
Thanks given by:
Posts: 496
Threads: 21
Joined: Apr 2013
05-27-2013, 04:21 PM
(This post was last modified: 06-01-2013, 10:10 AM by AmadisLFE.)
yeah well but if we cant stop LFE from being hacked then LFE will do unknown errors right
Edit:
well Simoneon's name was marked on may 22 why
Credits to PF for my Current Avatar, and Possibly my Rep Char F
Interested in Gaming? Check out my channel, its going to be updated soon.
You're just dying if you're living and thinking about a betrayal, revive yourself.
Think about that one person that has trusted you forever, not the thousand people that have betrayed you.
Thanks given by:
Posts: 820
Threads: 44
Joined: Mar 2011
(05-27-2013, 03:36 AM)Amadis Wrote: LFE needs a better antivirus system in think so that it cannot be hacked
Viruses do not hack web hosts.
Thanks given by:
Posts: 2,386
Threads: 48
Joined: Mar 2012
06-01-2013, 12:53 PM
(This post was last modified: 06-01-2013, 12:56 PM by Gespenst.)
(05-27-2013, 08:40 AM)MH-Razen Wrote: Everybody with suggestions for that problem is welcome. i suggest if you or bp dont have time, ask other lfe mods or admins who knows knows about this web rebuild thing and make them available to make it, Also you need person who have time and that person must be honest with no bad influence to lfe.
Useful
Thanks given by:
Posts: 746
Threads: 55
Joined: Apr 2008
06-01-2013, 01:01 PM
(This post was last modified: 06-01-2013, 01:02 PM by Som1Lse.)
(06-01-2013, 12:38 PM)Electric Shock Wrote: Viruses do not hack web hosts. As a matter of fact they can.
Say a computer gets infected with a virus that checks a server for instructions.
It might be instructed to keep connecting to a web server and thus overloading it.
That is the basic premise behind a bot net, that are a major player in DDoS attacks.
You are however right that it is not LFE that needs the antivirus software, but the computer that gets infected.
Age ratings for movies and games (and similar) have never been a good idea.
One can learn a lot from reinventing wheels.
An unsound argument is not the same as an invalid one.
volatile in C++ does not mean thread-safe.
Do not make APIs unnecessarily asynchronous.
Make C++ operator > again
Trump is an idiot.
Posts: 2,386
Threads: 48
Joined: Mar 2012
Indeed virus can affect almost everything. If not straight to to they can go around.
What if lfe could get replacement, like use other forum before lfe will be fixed?
Use lf2 official forum.
Useful
Thanks given by:
|