±Recent Visitors

Recent Visitors to Com-Central!

±User Info-big


Welcome Anonymous

Nickname
Password

Membership:
Latest: HighestAce
New Today: 0
New Yesterday: 0
Overall: 6648

People Online:
Members: 0
Visitors: 283
Total: 283
Who Is Where:
 Visitors:
01: Home
02: Community Forums
03: Photo Gallery
04: Community Forums
05: Member Screenshots
06: Home
07: Community Forums
08: Community Forums
09: Statistics
10: Home
11: Community Forums
12: CPGlang
13: Community Forums
14: Community Forums
15: CPGlang
16: Home
17: Downloads
18: Home
19: Community Forums
20: Community Forums
21: Community Forums
22: Community Forums
23: Photo Gallery
24: Member Screenshots
25: Home
26: Community Forums
27: Home
28: CPGlang
29: CPGlang
30: Community Forums
31: Home
32: Member Screenshots
33: Community Forums
34: Community Forums
35: Home
36: Home
37: Community Forums
38: Downloads
39: Community Forums
40: Photo Gallery
41: Community Forums
42: Community Forums
43: Statistics
44: Home
45: Home
46: Community Forums
47: Community Forums
48: Home
49: Home
50: Community Forums
51: Community Forums
52: Community Forums
53: CPGlang
54: Community Forums
55: News
56: Photo Gallery
57: Community Forums
58: Community Forums
59: Community Forums
60: Community Forums
61: Community Forums
62: Home
63: Member Screenshots
64: Home
65: Downloads
66: Community Forums
67: Photo Gallery
68: Community Forums
69: Home
70: Home
71: Home
72: Community Forums
73: Contact
74: CPGlang
75: Community Forums
76: Statistics
77: Photo Gallery
78: Community Forums
79: Downloads
80: Statistics
81: Home
82: Community Forums
83: Community Forums
84: Photo Gallery
85: Home
86: Home
87: Member Screenshots
88: Community Forums
89: Community Forums
90: News
91: Home
92: Home
93: Home
94: Home
95: Home
96: Photo Gallery
97: CPGlang
98: Home
99: Community Forums
100: Home
101: Photo Gallery
102: Community Forums
103: Home
104: Home
105: Home
106: Home
107: Home
108: Home
109: Community Forums
110: Community Forums
111: Home
112: Community Forums
113: Home
114: Home
115: Home
116: Downloads
117: Home
118: Community Forums
119: Home
120: Home
121: Community Forums
122: Home
123: Home
124: Member Screenshots
125: Home
126: Home
127: Home
128: Community Forums
129: Community Forums
130: CPGlang
131: Photo Gallery
132: Home
133: Home
134: Photo Gallery
135: Community Forums
136: Community Forums
137: Community Forums
138: News Archive
139: Community Forums
140: Community Forums
141: Community Forums
142: Community Forums
143: Community Forums
144: Home
145: Community Forums
146: Home
147: Community Forums
148: Community Forums
149: Community Forums
150: Home
151: Community Forums
152: Home
153: Home
154: Home
155: Community Forums
156: News
157: Photo Gallery
158: Community Forums
159: Community Forums
160: Community Forums
161: Community Forums
162: Community Forums
163: Community Forums
164: Home
165: Community Forums
166: Downloads
167: Community Forums
168: CPGlang
169: Community Forums
170: Downloads
171: Community Forums
172: Community Forums
173: Photo Gallery
174: Downloads
175: Home
176: CPGlang
177: News Archive
178: CPGlang
179: CPGlang
180: Home
181: Home
182: CPGlang
183: Community Forums
184: Home
185: Home
186: Home
187: Home
188: Home
189: Home
190: Home
191: Home
192: Home
193: CPGlang
194: Community Forums
195: Community Forums
196: Home
197: Community Forums
198: Home
199: Home
200: Home
201: Home
202: Home
203: Home
204: Home
205: News Archive
206: Community Forums
207: Home
208: Home
209: Photo Gallery
210: CPGlang
211: Home
212: Home
213: Home
214: Downloads
215: Member Screenshots
216: Home
217: Community Forums
218: Home
219: Home
220: Community Forums
221: Community Forums
222: Home
223: Home
224: Home
225: Community Forums
226: Supporters
227: Community Forums
228: Home
229: Home
230: Your Account
231: Home
232: Community Forums
233: Community Forums
234: Home
235: Downloads
236: Home
237: Community Forums
238: Home
239: Home
240: Home
241: Home
242: Community Forums
243: Home
244: Home
245: Community Forums
246: Home
247: Community Forums
248: Home
249: Home
250: Community Forums
251: Home
252: Member Screenshots
253: Community Forums
254: Community Forums
255: Community Forums
256: Home
257: Statistics
258: CPGlang
259: Home
260: Home
261: Contact
262: CPGlang
263: Community Forums
264: Photo Gallery
265: Home
266: Home
267: Home
268: Community Forums
269: Home
270: Community Forums
271: Home
272: Community Forums
273: Community Forums
274: Home
275: Home
276: Home
277: Community Forums
278: Community Forums
279: CPGlang
280: Community Forums
281: Home
282: Home
283: Community Forums

Staff Online:

No staff members are online!
Page themes fixed...
The AFV ASSOCIATION was formed in 1964 to support the thoughts and research of all those interested in Armored Fighting Vehicles and related topics, such as AFV drawings. The emphasis has always been on sharing information and communicating with other members of similar interests; e.g. German armor, Japanese AFVs, or whatever.
Go to page Previous  1, 2
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ›  AFV News Discussion Board

View previous topic :: View next topic  
Author Message
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Sun Feb 05, 2012 10:26 pm
Post subject: Re: Page themes fixed...

The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."
Back to top
View user's profile Visit poster's website Photo Gallery
Smashy
Power User

Offline Offline
Joined: Aug 05, 2010
Posts: 112

PostPosted: Mon Feb 06, 2012 12:09 am
Post subject: Re: Page themes fixed...

- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?

_________________
Smashy
Back to top
View user's profile
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Mon Feb 06, 2012 11:36 pm
Post subject: Re: Page themes fixed...

- Smashy
- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?



Here's the latest (and we can assume final) word on this subject:

"I'm still looking into this issue and this is what I've learned to date...

The BBcode code writers, (the code used on most forums and here at CC), has found a security issue with the older code which allowed spaces in the URL link. At the moment, the code writers are 'sticking to their guns' about not allowing spacing in URL's.

Some of the pic hosting sites on the web such as PhotoBucket allow using spaces in their URL's so it's going to be a bigger problem than some realize if those sites don't update their policies. It's too easy to include malicious code in broken (using spaces) URL's and that could include redirect scripts that would allow a hacker to point others to a different site than you had intended to use or inserting JAVA code to install hacker code into your personal computer.

A more 'techy' point of view:

One way to think about this problem is as well to check on server side that GET and POST request are not equivalent.

A POST request can alter data in server side, a GET request mustn't change anything. That's the HTTP protocol. An IMG tag is a GET request, always. And the browser can perform this GET request without any risk, so the problem is on server side, every action that can change alter data (database, session, etc) must check the request is a POST one. For example your /post url, should return asking for a POST confirmation. If this is wrong in your application, then you'll have problems not only with altered IMG tags, but maybe as well with 'html page speeders' that make preload of GET references, or even bots.

It's possible to 'force' (rewrite) the code, but I think we should error in the way of security as it's our duty to try to protect our users as much as possible."




Sorry for any inconvenience, but site and member safety come first, as it should be.
I'm no authority, but I have plenty of anecdotal experience that suggests that it's not good practice to include spaces in any filenames, etc....and it's also not wise to make them any longer than they have to be.
Back to top
View user's profile Visit poster's website Photo Gallery
Roy_A_Lingle
Power User

Offline Offline
Joined: Jan 24, 2006
Posts: 1997
Location: El Paso & Ft Bliss, Texas
PostPosted: Tue Feb 07, 2012 10:20 pm
Post subject: Re: Page themes fixed...

Hi Doug! Hi Folks!

Thanks for the update! The last thing we all need is to lose another site.

Sgt, Scouts out!

_________________
"You can never have too much reconnaissance."
General G.S. Patton Jr.
Back to top
View user's profile Send e-mail
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ›  AFV News Discussion Board
Page 2 of 2
All times are GMT - 6 Hours
Go to page Previous  1, 2



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum