vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Moderators Functions - Hidden Image Checker by BOP5 for VB 3.x and VB 4.x (Stop Cookie Stuffing!) (https://vborg.vbsupport.ru/showthread.php?t=280952)

BirdOPrey5 04-02-2012 11:25 AM

Images that use the [img] bbcode are counted regardless of the domain they are on... So even if you are using [img] to link to local images (for some reason) they would count as an image.

BirdOPrey5 04-09-2012 02:16 PM

There is a known conflict with DbTech's Advanced Post Thanks/Like mod. Thanks to Alan_SP for finding which mod conflicted.

I don't see any way of making them compatible so just skip this mod if you use the dbtech one.

The problem is dbtech parses bbcode of $post[pagetext] when it is supposed to be raw bbcode, not parsed. It means this mod can't find or count [img] bbcodes.

Alan_SP 04-10-2012 10:00 AM

I have to say that at the moment I'm still using older version of DBTech's APTL (v1.1.9) so there's a slight chance that with newer versions it might work.

BirdOPrey5 04-12-2012 11:46 AM

Version 1.02 - Compatibility fix for dbtech Advanced Thanks/Like mod

Alan_SP 04-12-2012 07:21 PM

Thanks, this version fixes compatibility with DBTech's mod. :up:

Now everything works as it should on my site. :)

P.S At the moment I couldn't like your post, otherwise I would. :(

megabink 04-14-2012 10:22 PM

This is really great stuff,installed and nominated.
Thanks

Budget101 02-17-2015 12:23 PM

I'm new to the cookie stuffing concept, bear with me if this question is retarded, but, if members Upload images using the default image uploader can they embed code in that as well?? Or does this just affect the bbcode [img] tag?

Alan_SP 02-17-2015 02:57 PM

Idea is that image is on some other server, as explained in the first post:

Quote:

Cookie stuffing is when a malicious user posts a hidden (clear) image in a post. Although you may never see the image it actually links to a location that will set a cookie on the browser of everyone viewing the post. In the cases of cookie stuffing this is almost always a cookie that contains their affiliate code for a site like Amazon or eBay. If anyone on your forum should go on to buy something from Amazon.com later in the day the spammer will get a credit from Amazon because your user has the spammer's cookie on their computer.
Attached images are on your server. Image doesn't have information, but location where image is does. That's the idea. So, only images on other servers may be a problem.

Budget101 02-17-2015 05:47 PM

Quote:

Originally Posted by Alan_SP (Post 2537777)
Attached images are on your server. Image doesn't have information, but location where image is does. That's the idea. So, only images on other servers may be a problem.

Thank you for your reply Alan, that was my understanding as well, but I wanted to be clear. I wasn't sure if there was some way for hackers to embed additional coding in the image prior to uploading to the server. I'm trying to cover all my bases after discovering malicious code on my site.

da_judge 02-17-2015 08:06 PM

another great adition... thanks


All times are GMT. The time now is 09:45 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01131 seconds
  • Memory Usage 1,730KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete