Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 04-16-2003, 09:28 PM
Gutspiller's Avatar
Gutspiller Gutspiller is offline
 
Join Date: Dec 2001
Posts: 1,046
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I think bbcode has it's limits. Back when I was changing up my bbcode more often than I am now, if I remember right, bbcode can't do 2 options only one. Personally I kinda thought bbcode was limited. I have wav files enabled for posting, flash files. People can post images stating both the height and width the image. I think with bbcode, you can't tell it what you want the height and the width to be. You can put an option when you are creating the bbcode, but then that option would have to be both the width and height. That is if I remember right.

I do remember one reason why I need html enabled. The smilies that I have above the text field where people type their images are clickable. I believe it's using one of Fireflys hacks. to insert the smilie into the users post it adds the image using a line like this:

Code:
<img src=images/icons/icon180.gif>
I might be able to dig up the hack with the instructions and maybe somebody could look at it for me and see if they could get the same hack to work without having to have html enabled for the board to recognize the smilies that are inserted into posts?

I think that was the main reason why I add html turned on.

I do however have the following commands in my censorship area:

Code:
<style </style <iframe </iframe <link </link <basefont </basefont <base </base <th </th <tfoot </tfoot <tbody </tbody <thead </thead <body </body <meta </meta <script </script <html </html <plaintext </plaintext <xmp </xmp <object <noframes <noembed <noscript <nojava onload onMouseover <fieldset :absolute style="position "position absolute; <caption
Those alone seem to keep out the nastier ones I have found some of my members using. With all those censored, I believe I have very little to no holes with the enabled html, however I know that there are probably some that I have missed, so if somebody is willing to help me get that hack that I mentioned above to get it to work without html, I would be willing to switch.
Reply With Quote
  #12  
Old 04-16-2003, 09:33 PM
filburt1 filburt1 is offline
 
Join Date: Feb 2002
Location: Maryland, US
Posts: 6,144
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

How about this seemingly innocent thing?
Code:
<a href="#" onMouseOut="doBadStuff()">
The point is you must turn it off or your site will eventually be hacked.
Reply With Quote
  #13  
Old 04-19-2003, 07:38 AM
Gutspiller's Avatar
Gutspiller Gutspiller is offline
 
Join Date: Dec 2001
Posts: 1,046
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
04-16-03 at 03:33 PM filburt1 said this in Post #12
How about this seemingly innocent thing?
Code:
<a href="#" onMouseOut="doBadStuff()">
The point is you must turn it off or your site will eventually be hacked.
Just added onmouseout to censored words, now it will appear as

Code:
<a href="#" **********="doBadStuff()">
See, not that hard. Just need help with peep thinking of other words to censor so they don't run. I think it's possible to run html if you do this and if I get some more help on other html "commands" to censor.
Reply With Quote
  #14  
Old 04-19-2003, 03:20 PM
filburt1 filburt1 is offline
 
Join Date: Feb 2002
Location: Maryland, US
Posts: 6,144
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You dont understand. There are possibly literally hundreds of ways to execute Javascript on a page. Just turn off HTML and the risk will be gone.
Reply With Quote
  #15  
Old 04-19-2003, 06:58 PM
Gutspiller's Avatar
Gutspiller Gutspiller is offline
 
Join Date: Dec 2001
Posts: 1,046
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Today at 09:20 AM filburt1 said this in Post #14
You dont understand. There are possibly literally hundreds of ways to execute Javascript on a page. Just turn off HTML and the risk will be gone.
What makes VBcode so safe if it uses html too? :ermm:
Reply With Quote
  #16  
Old 04-19-2003, 07:27 PM
filburt1 filburt1 is offline
 
Join Date: Feb 2002
Location: Maryland, US
Posts: 6,144
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Because you have complete control over what HTML it uses, and it scrubs any HTML the user sends.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:50 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03943 seconds
  • Memory Usage 2,214KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (5)bbcode_code
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (6)post_thanks_box
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete