±Recent Visitors

Recent Visitors to Com-Central!

±User Info-big


Welcome Anonymous

Nickname
Password

Membership:
Latest: cgsimpson
New Today: 0
New Yesterday: 0
Overall: 6645

People Online:
Members: 0
Visitors: 128
Total: 128
Who Is Where:
 Visitors:
01: Community Forums
02: Community Forums
03: Home
04: Member Screenshots
05: Community Forums
06: Home
07: Home
08: Community Forums
09: Home
10: Community Forums
11: Home
12: Community Forums
13: CPGlang
14: Home
15: Home
16: Home
17: Home
18: Community Forums
19: Home
20: Home
21: Community Forums
22: Community Forums
23: Home
24: Home
25: Community Forums
26: Home
27: Community Forums
28: Home
29: Community Forums
30: Home
31: Home
32: Home
33: Home
34: Downloads
35: Community Forums
36: Home
37: Community Forums
38: Home
39: Downloads
40: Home
41: Community Forums
42: Home
43: Home
44: Community Forums
45: Community Forums
46: Your Account
47: Home
48: Home
49: Community Forums
50: Community Forums
51: Your Account
52: Community Forums
53: Community Forums
54: Community Forums
55: Community Forums
56: Community Forums
57: Community Forums
58: Community Forums
59: Community Forums
60: Home
61: News Archive
62: Home
63: Home
64: Downloads
65: Home
66: Home
67: Community Forums
68: Home
69: Community Forums
70: Community Forums
71: Community Forums
72: Home
73: Community Forums
74: Community Forums
75: Community Forums
76: Photo Gallery
77: Photo Gallery
78: Home
79: Home
80: Community Forums
81: Community Forums
82: Home
83: Community Forums
84: Community Forums
85: Community Forums
86: Home
87: Home
88: News
89: Home
90: Home
91: Home
92: Home
93: Community Forums
94: Downloads
95: Home
96: Community Forums
97: Community Forums
98: Photo Gallery
99: Community Forums
100: Community Forums
101: Community Forums
102: Downloads
103: Community Forums
104: Community Forums
105: Community Forums
106: Community Forums
107: Community Forums
108: Photo Gallery
109: Community Forums
110: Photo Gallery
111: Community Forums
112: Community Forums
113: Community Forums
114: Community Forums
115: Photo Gallery
116: Home
117: Downloads
118: Community Forums
119: Downloads
120: Community Forums
121: Community Forums
122: Downloads
123: Statistics
124: Home
125: Downloads
126: Home
127: Photo Gallery
128: Home

Staff Online:

No staff members are online!
Page themes fixed...
The AFV ASSOCIATION was formed in 1964 to support the thoughts and research of all those interested in Armored Fighting Vehicles and related topics, such as AFV drawings. The emphasis has always been on sharing information and communicating with other members of similar interests; e.g. German armor, Japanese AFVs, or whatever.
Go to page Previous  1, 2
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ›  AFV News Discussion Board

View previous topic :: View next topic  
Author Message
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Sun Feb 05, 2012 10:26 pm
Post subject: Re: Page themes fixed...

The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."
Back to top
View user's profile Visit poster's website Photo Gallery
Smashy
Power User

Offline Offline
Joined: Aug 05, 2010
Posts: 112

PostPosted: Mon Feb 06, 2012 12:09 am
Post subject: Re: Page themes fixed...

- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?

_________________
Smashy
Back to top
View user's profile
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Mon Feb 06, 2012 11:36 pm
Post subject: Re: Page themes fixed...

- Smashy
- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?



Here's the latest (and we can assume final) word on this subject:

"I'm still looking into this issue and this is what I've learned to date...

The BBcode code writers, (the code used on most forums and here at CC), has found a security issue with the older code which allowed spaces in the URL link. At the moment, the code writers are 'sticking to their guns' about not allowing spacing in URL's.

Some of the pic hosting sites on the web such as PhotoBucket allow using spaces in their URL's so it's going to be a bigger problem than some realize if those sites don't update their policies. It's too easy to include malicious code in broken (using spaces) URL's and that could include redirect scripts that would allow a hacker to point others to a different site than you had intended to use or inserting JAVA code to install hacker code into your personal computer.

A more 'techy' point of view:

One way to think about this problem is as well to check on server side that GET and POST request are not equivalent.

A POST request can alter data in server side, a GET request mustn't change anything. That's the HTTP protocol. An IMG tag is a GET request, always. And the browser can perform this GET request without any risk, so the problem is on server side, every action that can change alter data (database, session, etc) must check the request is a POST one. For example your /post url, should return asking for a POST confirmation. If this is wrong in your application, then you'll have problems not only with altered IMG tags, but maybe as well with 'html page speeders' that make preload of GET references, or even bots.

It's possible to 'force' (rewrite) the code, but I think we should error in the way of security as it's our duty to try to protect our users as much as possible."




Sorry for any inconvenience, but site and member safety come first, as it should be.
I'm no authority, but I have plenty of anecdotal experience that suggests that it's not good practice to include spaces in any filenames, etc....and it's also not wise to make them any longer than they have to be.
Back to top
View user's profile Visit poster's website Photo Gallery
Roy_A_Lingle
Power User

Offline Offline
Joined: Jan 24, 2006
Posts: 1997
Location: El Paso & Ft Bliss, Texas
PostPosted: Tue Feb 07, 2012 10:20 pm
Post subject: Re: Page themes fixed...

Hi Doug! Hi Folks!

Thanks for the update! The last thing we all need is to lose another site.

Sgt, Scouts out!

_________________
"You can never have too much reconnaissance."
General G.S. Patton Jr.
Back to top
View user's profile Send e-mail
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ›  AFV News Discussion Board
Page 2 of 2
All times are GMT - 6 Hours
Go to page Previous  1, 2



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum