One of our members pointed out that anyone can find out and record the IP-address of anyone viewing a thread, simply by posting a hotlinked image (with the IMG tags).
As you may know, it works like this: they host the image on a private server, then add an .htaccess file that redirects the image to a PHP script that records every IP of who viewed the image to a database. The script then shows the image to the user who is not aware of anything.
This is a security issue on every forum allowing embedding he says. My question: does XF has a build in feature to work around this issue? Or is custom coding required?
As you may know, it works like this: they host the image on a private server, then add an .htaccess file that redirects the image to a PHP script that records every IP of who viewed the image to a database. The script then shows the image to the user who is not aware of anything.
This is a security issue on every forum allowing embedding he says. My question: does XF has a build in feature to work around this issue? Or is custom coding required?