Results 1 to 11 of 11
Like Tree2Likes
  • 1 Post By just4kix
  • 1 Post By Admin

Thread: Attachment permissions

  1. #1
    Admin's Avatar
    Join Date
    Jan 2006
    Liked
    57 times
    Posts
    6,150

    Default Attachment permissions

    Hello Members,

    I had to disable the use of attachments and images on the forum because someone has been trying to upload a .php file disguised as an image file and have been trying to execute it remotely and this has happened more then once but due to some security measures we have in place our forum was not compromised and these attempts are on the rise and we cannot risk the whole forum going down due to this.

    I will enable attachments as soon as I find a solution to this problem. Sorry about the inconvenience.

    Thanks
    Parminder

  2. #2
    Tech Crazy!! sarveshmotihari's Avatar
    Join Date
    Jan 2012
    Liked
    143 times
    Posts
    575

    Default

    No problem Admin. Forum's safety is most important....Till then we can upload file on any other server and can give link in the forum..

  3. #3
    LEARNER
    Join Date
    Aug 2007
    Liked
    28 times
    Posts
    15,323

    Default

    You can reduce the size of the attachments, and disallow *.zip and *.rar formats.
    I feel for a JPG/PNG say 100 KB will do.
    ( Also for Insert mode )

  4. #4
    Platinum Member mickey's Avatar
    Join Date
    Jan 2009
    Liked
    16 times
    Posts
    6,990

    Default

    thanks for checking that admin..

  5. #5
    Platinum Member mickey's Avatar
    Join Date
    Jan 2009
    Liked
    16 times
    Posts
    6,990

    Default

    alternate ways to attachments:-

    have a google account.
    sites.google.com
    make your unlimited sites on it..(thats what google actually wanted.. spam 'em)
    now open any site for edit.. (its easy, it will happen like a ms-doc stuff)
    attach your file.. (or you can directly attach your file on the page bottom)
    now link the file here.. its safe+google won't allow fake stuff going into attachments..

    @admin
    btw forums are best place for "peeps" to put their codes because of the html and java ability.. its a basic vulnerability of a phbb that cant be wholly terminated..
    Site from home gaya bhad mein... AIrtel se bolo FUP band kare.. BSNl se bolo 3G signal do!!!!>: (

  6. #6
    Admin's Avatar
    Join Date
    Jan 2006
    Liked
    57 times
    Posts
    6,150

    Default

    Quote Originally Posted by essbebe View Post
    You can reduce the size of the attachments, and disallow *.zip and *.rar formats.
    I feel for a JPG/PNG say 100 KB will do.
    ( Also for Insert mode )
    Someone has been uploading .php files disguised as .jpg and executed it remotely. I have restricted remote execution somehow but there are still loopholes and all vbulletin forums are at risk not just this. will find a way out soon.

  7. #7
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Liked
    118 times
    Posts
    11,161

    Default

    Is there any option to block attachments before, say 100, posts? I guess not.
    Admin likes this.

  8. #8
    Admin's Avatar
    Join Date
    Jan 2006
    Liked
    57 times
    Posts
    6,150

    Default

    There must be a mod available for that. Will try and find one.

  9. #9
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Liked
    118 times
    Posts
    11,161

    Default

    Actually many forums allow limited attachments only. They suggest using file hosting sites for attachments.

  10. #10
    Admin's Avatar
    Join Date
    Jan 2006
    Liked
    57 times
    Posts
    6,150

    Default

    We have a mod in place now will sort out the settings before I go to sleep tonight
    just4kix likes this.

  11. #11
    Platinum Member mickey's Avatar
    Join Date
    Jan 2009
    Liked
    16 times
    Posts
    6,990

    Default

    well in this forum people can have their files hosted on some third party and paste the image url here..

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Problem in attachment
    By pkm.sbp in forum Computer technology
    Replies: 13
    Last Post: 10-29-11, 11:46 PM
  2. Avatar permissions
    By Admin in forum Suggestions and Complaints
    Replies: 1
    Last Post: 11-22-10, 11:10 PM
  3. Security Permissions/Procedure to start Cybercafe
    By kash_1210 in forum BSNL broadband
    Replies: 5
    Last Post: 08-29-09, 10:55 PM
  4. prob regarding mail attachment
    By prasanta08 in forum Software News, Previews and Reviews
    Replies: 2
    Last Post: 09-28-08, 02:32 AM
  5. BSNL Connection and attachment problem...
    By itheniks in forum BSNL broadband
    Replies: 8
    Last Post: 06-05-08, 04:22 PM