Protect images Protect images
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Protect images

Started by smileylanz, July 17, 2006, 08:56:50 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

smileylanz

My coppermine gallery is strictly for members only. Guests can view thumbnails but not the actual images, but I stumbled upon this: http://users.livejournal.com/_jems_/267839.html

This allows users who aren't registered to not only see the images, but download entire albums of images directly to their computers, which is very bad for me as albums have thousands of images on my site and I pay for my site by displaying ads on each page view. If visitors do this, they get all of the images without registering or seeing the site page views.

Is there any way to protect my site from this?

Joachim Müller

Turn indexes off ("Options -Indexes" in .htaccess) and the pretty crude instructions posted on the site you're refering to are rendered invalid.
However, determined users who know their way around and know how coppermine actually works can't be kept from stealing your pics if you allow them to see the thumbails.


Stramm

If you modded coppemine the way that only registered users can view normal and fullsized pics, then there shouldn't be links to these pics in the html. Hence a download manager can't get them

The download manager discussion is some years old and back the days everybody was afraid of them and tried to find ways how to block them (htaccess was a solution). But these programs can mask themeselves as eg a Mozilla browser. Means you won't have luck really blocking them all. Another solution was some hidden link on the page. If it got hit then only a bot can do it. The link started a small script that checked the bots IP, compared it with good bot IPs and if it wasn't on the list the bot got blocked for a few mins.
Another attempts were made with counting the number of clicks in a certain timeframe. If clicked two often in eg 30 secs ... IP blocked