Announcement

Collapse
No announcement yet.

Static images vs animated images

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Static images vs animated images

    I recently got told that putting animated images (avatars, signatures...) on the boards is usually bad idea because of the security issues.

    Can someone explain it why?

    For instance, here at the vBulletin boards, they (admins) don´t allow the members to have avatars or signatures for that matter.
    Why is that?

  • #2
    We allow avatars and signatures on our forums.

    Comment


    • #3
      We just dont allow animated avatars because they annoy us, thats all
      Scott MacVicar

      My Blog | Twitter

      Comment


      • #4
        So thats why that setting was added. LOL!
        L'chaim

        Comment


        • #5
          I probably read the thread on other forum.

          One guy complained that his board was hacked and he is a security freak.
          Then, another member replied by saying that animated pictures is a bad idea to have on your forums because the hackers can take advantage of it.

          Just wanted to know if this is true.

          Comment


          • #6
            Perhaps he allowed dynamic image URL's. That perhaps end with something like image.gif?blah=moo .. this could lead to code injections when abused, vBulletin offers to turn this dynamic img urls to be on/off and is off by default.

            Allowing HTML in posts, private messages and signatures also opens your forum up to such abuse.

            Perhaps he was running an older version, with known security issues. We always recommend to run the latest stable release.

            Comment


            • #7
              Originally posted by Floris
              Perhaps he allowed dynamic image URL's. That perhaps end with something like image.gif?blah=moo .. this could lead to code injections when abused, vBulletin offers to turn this dynamic img urls to be on/off and is off by default.

              Allowing HTML in posts, private messages and signatures also opens your forum up to such abuse.

              Perhaps he was running an older version, with known security issues. We always recommend to run the latest stable release.
              where do i check if mine is set to off???

              and isnt there a search function in the admincp so i could search for stuff like this???
              My site
              www.coolservice.dk

              Comment


              • #8
                To check it make a post in your forums and add the following in [img]-Tags:

                http://www.vbulletin.com/forum/image...ine=1104886134


                If you allow dynamic image url's Floris' avatar will show up
                That's the end of that!

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...
                X