![]() |
Quote:
|
VERY SORRY...
.... the mozilla noscript extention was blocking the install.htm file from loading properly. |
Anyone know the quickest way to disable autoplay / autostart (even if users enables it in the MEDIA tags) ?
Is it possible to hardcode a value of 0 / no / false somewhere for the autoplay value? Maybe something around here in includes/class_anymedia.php? PHP Code:
Or maybe it would just be easier to strip the media tag flags when they are submitted (if you're worried about getting thread-DOS'ed via autoplay) |
Quote:
will this code work for google using anymedia flash player ( not google flash player) |
nope.
|
Quote:
You have version 8,0,24,0 installed I'm baffled... can't view it on 4 machines... its fine in firefox... any idea people? |
I am good up until the final step. I cannot find the "Anymedia bbcode permissions."
I am looking in the usergroup permissions but do not see it. Am I missing something? |
Maybe redo your bitfield so it updates, Then try.
My concern is.. I am not secure about using this.. seems users could spam flash players all over a thread.. =/ Wonder what everyone does to secure this. |
Quote:
There are definitely some security issues to consider when using this module. #1: Think strongly about allowing macromedia files to be one of the file types that are allowed to play. (ie .swf and the other 2 in that row). It's very easy for someone to construct a .swf that will redirect your member to a url of the .swf authors choosing. Perhaps the site they redirect them to looks just like YOUR sites login page? Making the user think they are logged out and they need to log in again. But instead, the flash author harvests their password & logs them in to your board as if nothing happened. #2: As mysticales says above, and I have said, and someone else originally said in this thread... there is potential for per-thread denial of service attacks. The attacker would just need to make a few posts and autoplay 20-30 large files. Suggested fixes: For #1: There's no fix really, unless your server pulls the submitted .swf or flash file on submission, scans it for anything you consider malicious, and then hosts it locally. Scanning a hotlinked .swf & leaving it that way would do no good because the person could just change the .swf file to something malicious later. Btw, I'm think the same goes for certain windows media files as well... .asf and .asx I believe. For #2: Add options to limit things like: - The number of media tags a user can enter per day - The number of media tag allowed per thread And most importantly: Ignore user-submitted autoplay? (YES) / NO |
Quote:
Because of concerns like this only Admin/Mods are even allowed to use this on my forum. Still a wonderful addition to the forum though. :D |
All times are GMT. The time now is 05:06 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|