This suggestion has been closed automatically because it did not receive enough votes over an extended period of time. If you wish to see this, please search for an open suggestion and, if you don't find any, post a new one.
not the same, even if attachments are disabled in conversations it doesn't stop people from clicking the insert image icon and inserting an image into a conversation
Without being able to disable this function, its possible for members to obtain ip's of other members very easily.
not the same, even if attachments are disabled in conversations it doesn't stop people from clicking the insert image icon and inserting an image into a conversation
Without being able to disable this function, its possible for members to obtain ip's of other members very easily.
From what I understand this can only occur if the forum software doesn't do basic checks for a valid image. Have you seen this exploit on Xenforo forums actually work?
only way to stop it is to give option to disable img code in conversations.
then with it disabled from usergroup permissions if some one wanted to send an img they would have to type the url and it would be up to the person recieving the pm whether they wanted to visit that url or not, but it would be at their own risk and probably if they trusted the sender
Its not really an exploit; you are accessing a file from a server (be it an attachment or located elsewhere), your IP address will most likely appear in the server access log. That is standard on pretty much every server.
Its not really an exploit; you are accessing a file from a server (be it an attachment or located elsewhere), your IP address will most likely appear in the server access log. That is standard on pretty much every server.
an image can be any script that returns an image header and image data, the viewer sees the image, the script can see the viewer's IP.... that's why many email readers don't show images without viewer approval
an image can be any script that returns an image header and image data, the viewer sees the image, the script can see the viewer's IP.... that's why many email readers don't show images without viewer approval
Isn't it much simpler than that? You could do it with the regular image, which the victim would request to show and the host would record what IP the request came from. That's probably the more straightforward reason why most mail clients prevent image-loading unless approved.