Image Path URL Easy to Hack ? Image Path URL Easy to Hack ?
 

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Main Menu

Image Path URL Easy to Hack ?

Started by rostros, September 13, 2004, 12:21:49 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

rostros

Im sure I have seen one of these related threads before but could not find it.

Anyways My CPG has members and I have it so only Registered Members can See Full Size Only, and Un-Registered Members can see the Thumbnail and Intermediate Photo, I have noticed that there is an Easy hack to see the Full Size image, once the intermediate photo is loaded, the Un registered user can right click and view the Photo URL Path e.g

                  http:yoursite.com/cpg/images/gallery/normal_image.jpg  

Then all they need to do is delete the Normal_ and they have the ability to view the full picture using a direct path, also this is a problem as image hotlinking to other sites is a big problem for me.

I have currently got a Javascript disabling the right click on images but I would like to be able to remove this as right click is a popular choice when looking at images.

Any Help would be great  :)

Casper

It has been a long time now since I did my little bit here, and have done no coding or any other such stuff since. I'm back to being a noob here

TyL

Ok but don't work on apache & windows :(

Tranz

I think that code just prevents hotlinking, but not direct access from the browser address bar.

Try this: http://forum.coppermine-gallery.net/index.php?topic=3021.msg45672#msg45672

But I don't know if it is specific to linux/unix.

@TyL: Also, since you have multiple questions, please specify what doesn't work and how it doesn't work.

Tarique Sani

You can have an .htaccess file check for referer and see if it is displayimage.php of your site - basically the same principle as the prevention of hotlinking - AFAIK .htaccess will work just the same on Apache for windows as it does for *nix

But still my contention is if it is on the web it is stealable - may be you should really look at session based one time URL generation
SANIsoft PHP applications for E Biz