±Recent Visitors

Recent Visitors to Com-Central!

±User Info-big


Welcome Anonymous

Nickname
Password

Membership:
Latest: HighestAce
New Today: 0
New Yesterday: 0
Overall: 6648

People Online:
Members: 0
Visitors: 451
Total: 451
Who Is Where:
 Visitors:
01: Home
02: Home
03: Community Forums
04: Downloads
05: Home
06: Home
07: Home
08: Home
09: Home
10: Home
11: Photo Gallery
12: Home
13: Downloads
14: Home
15: News Archive
16: Home
17: Photo Gallery
18: Community Forums
19: Community Forums
20: Home
21: Community Forums
22: Community Forums
23: Community Forums
24: Community Forums
25: Community Forums
26: Community Forums
27: Downloads
28: Home
29: Home
30: Home
31: Community Forums
32: Home
33: News
34: Home
35: Community Forums
36: Home
37: Home
38: Home
39: Home
40: Community Forums
41: Downloads
42: Community Forums
43: Downloads
44: Community Forums
45: Community Forums
46: Home
47: Community Forums
48: Member Screenshots
49: Community Forums
50: Community Forums
51: Photo Gallery
52: Home
53: Downloads
54: Community Forums
55: Community Forums
56: Community Forums
57: Community Forums
58: Downloads
59: Photo Gallery
60: Community Forums
61: Community Forums
62: Home
63: Community Forums
64: Photo Gallery
65: Home
66: Downloads
67: Community Forums
68: Community Forums
69: Community Forums
70: Home
71: News Archive
72: Home
73: Home
74: Community Forums
75: Community Forums
76: Community Forums
77: Home
78: Photo Gallery
79: Community Forums
80: Home
81: Community Forums
82: Community Forums
83: Community Forums
84: Community Forums
85: Photo Gallery
86: Home
87: Community Forums
88: News Archive
89: Home
90: Member Screenshots
91: Community Forums
92: Community Forums
93: Community Forums
94: Home
95: Home
96: Statistics
97: Home
98: Member Screenshots
99: Home
100: Community Forums
101: News Archive
102: Community Forums
103: Home
104: Home
105: Community Forums
106: Home
107: Community Forums
108: Photo Gallery
109: Home
110: Community Forums
111: Member Screenshots
112: Downloads
113: Home
114: Photo Gallery
115: Home
116: Community Forums
117: Member Screenshots
118: Community Forums
119: Home
120: Community Forums
121: Community Forums
122: Home
123: Community Forums
124: Statistics
125: Home
126: Home
127: Home
128: Home
129: Home
130: Photo Gallery
131: Home
132: Community Forums
133: Home
134: Home
135: Member Screenshots
136: Downloads
137: Community Forums
138: Home
139: Member Screenshots
140: Community Forums
141: Home
142: Community Forums
143: Home
144: Community Forums
145: Community Forums
146: Photo Gallery
147: Community Forums
148: Community Forums
149: Community Forums
150: Member Screenshots
151: Community Forums
152: Home
153: Community Forums
154: Community Forums
155: Photo Gallery
156: Community Forums
157: Photo Gallery
158: Community Forums
159: Home
160: Home
161: Home
162: Home
163: Member Screenshots
164: Home
165: Community Forums
166: Community Forums
167: Community Forums
168: Community Forums
169: Home
170: Community Forums
171: Home
172: Community Forums
173: Photo Gallery
174: Home
175: Downloads
176: Home
177: Photo Gallery
178: Home
179: Community Forums
180: Home
181: Community Forums
182: Home
183: Home
184: Community Forums
185: Member Screenshots
186: Downloads
187: Community Forums
188: Statistics
189: Home
190: Photo Gallery
191: Home
192: Home
193: Home
194: Home
195: Home
196: Member Screenshots
197: Community Forums
198: News Archive
199: Home
200: Home
201: Home
202: Community Forums
203: Community Forums
204: Community Forums
205: Home
206: Community Forums
207: Community Forums
208: Home
209: Downloads
210: Member Screenshots
211: Home
212: Home
213: Community Forums
214: Community Forums
215: Community Forums
216: Member Screenshots
217: Home
218: Community Forums
219: Member Screenshots
220: Community Forums
221: Community Forums
222: Home
223: Home
224: Community Forums
225: Community Forums
226: Home
227: Home
228: News
229: Home
230: News Archive
231: Your Account
232: Home
233: Home
234: Home
235: Home
236: Member Screenshots
237: Downloads
238: Community Forums
239: News
240: Community Forums
241: Photo Gallery
242: Community Forums
243: Community Forums
244: Photo Gallery
245: Community Forums
246: Member Screenshots
247: Community Forums
248: Photo Gallery
249: Community Forums
250: Home
251: Home
252: Photo Gallery
253: Home
254: Home
255: Downloads
256: Member Screenshots
257: Home
258: Community Forums
259: Community Forums
260: Home
261: Community Forums
262: Home
263: Community Forums
264: Community Forums
265: Home
266: Member Screenshots
267: Photo Gallery
268: Downloads
269: Home
270: Community Forums
271: Home
272: Downloads
273: Community Forums
274: Community Forums
275: Home
276: Home
277: Community Forums
278: Community Forums
279: Community Forums
280: Community Forums
281: Community Forums
282: Photo Gallery
283: Home
284: Home
285: Community Forums
286: Member Screenshots
287: Home
288: Community Forums
289: Community Forums
290: Community Forums
291: Home
292: Home
293: Community Forums
294: Community Forums
295: Downloads
296: Home
297: Home
298: Home
299: Community Forums
300: Home
301: Home
302: Home
303: Home
304: Photo Gallery
305: Photo Gallery
306: Community Forums
307: Home
308: Community Forums
309: Home
310: Home
311: Member Screenshots
312: Home
313: Home
314: Home
315: Photo Gallery
316: Home
317: Community Forums
318: Home
319: Home
320: Community Forums
321: Community Forums
322: Member Screenshots
323: Home
324: Community Forums
325: Photo Gallery
326: Home
327: Home
328: Community Forums
329: Community Forums
330: Photo Gallery
331: Home
332: Photo Gallery
333: Home
334: Community Forums
335: Home
336: Downloads
337: Photo Gallery
338: Community Forums
339: Community Forums
340: Community Forums
341: Community Forums
342: Home
343: Community Forums
344: Community Forums
345: Community Forums
346: Community Forums
347: Photo Gallery
348: Community Forums
349: Downloads
350: Home
351: Home
352: Home
353: Community Forums
354: Community Forums
355: Community Forums
356: Home
357: Member Screenshots
358: Home
359: Community Forums
360: Community Forums
361: Community Forums
362: Home
363: Home
364: Community Forums
365: Community Forums
366: Community Forums
367: Community Forums
368: Community Forums
369: Community Forums
370: Home
371: Photo Gallery
372: Home
373: Community Forums
374: Home
375: Home
376: Community Forums
377: Community Forums
378: Home
379: Community Forums
380: Home
381: Your Account
382: Members List
383: Home
384: Home
385: Home
386: Home
387: Home
388: Home
389: Community Forums
390: Member Screenshots
391: Member Screenshots
392: Home
393: Photo Gallery
394: Home
395: Home
396: Home
397: Community Forums
398: Photo Gallery
399: Home
400: Home
401: Community Forums
402: Community Forums
403: Community Forums
404: Home
405: News Archive
406: Member Screenshots
407: Photo Gallery
408: Community Forums
409: Community Forums
410: Community Forums
411: Community Forums
412: Community Forums
413: Community Forums
414: News
415: Community Forums
416: Community Forums
417: Community Forums
418: Community Forums
419: Community Forums
420: Home
421: News Archive
422: Home
423: Home
424: Community Forums
425: Home
426: Downloads
427: Home
428: Home
429: Photo Gallery
430: Downloads
431: Member Screenshots
432: Home
433: Photo Gallery
434: Home
435: Photo Gallery
436: Downloads
437: Photo Gallery
438: Community Forums
439: Home
440: Community Forums
441: Home
442: Community Forums
443: Community Forums
444: Community Forums
445: Community Forums
446: Photo Gallery
447: Home
448: Home
449: Community Forums
450: Community Forums
451: Community Forums

Staff Online:

No staff members are online!
Page themes fixed...
The AFV ASSOCIATION was formed in 1964 to support the thoughts and research of all those interested in Armored Fighting Vehicles and related topics, such as AFV drawings. The emphasis has always been on sharing information and communicating with other members of similar interests; e.g. German armor, Japanese AFVs, or whatever.
Go to page Previous  1, 2
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ›  AFV News Discussion Board

View previous topic :: View next topic  
Author Message
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Sun Feb 05, 2012 10:26 pm
Post subject: Re: Page themes fixed...

The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."
Back to top
View user's profile Visit poster's website Photo Gallery
Smashy
Power User

Offline Offline
Joined: Aug 05, 2010
Posts: 112

PostPosted: Mon Feb 06, 2012 12:09 am
Post subject: Re: Page themes fixed...

- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?

_________________
Smashy
Back to top
View user's profile
Doug_Kibbey
Power User

Offline Offline
Joined: Jan 23, 2006
Posts: 4678
Location: The Great Satan
PostPosted: Mon Feb 06, 2012 11:36 pm
Post subject: Re: Page themes fixed...

- Smashy
- Doug_Kibbey
The chief building superintendent sez:

"I've come across some information on this. Since the update prior to this last one, the updated BBcode has changed and that new change will not allow spaces in the URL link. A request to revamp the code has been made..."

...roughly meaning: "We've asked, and are awaiting a response, about which we haven't a lot of say."


This is very important as linux web servers allow users to create folder names & file names with spaces in them and there are a heck of a lot of linux web servers out there.

If I remember correctly the workaround is you must surround the filename with quotation marks?



Here's the latest (and we can assume final) word on this subject:

"I'm still looking into this issue and this is what I've learned to date...

The BBcode code writers, (the code used on most forums and here at CC), has found a security issue with the older code which allowed spaces in the URL link. At the moment, the code writers are 'sticking to their guns' about not allowing spacing in URL's.

Some of the pic hosting sites on the web such as PhotoBucket allow using spaces in their URL's so it's going to be a bigger problem than some realize if those sites don't update their policies. It's too easy to include malicious code in broken (using spaces) URL's and that could include redirect scripts that would allow a hacker to point others to a different site than you had intended to use or inserting JAVA code to install hacker code into your personal computer.

A more 'techy' point of view:

One way to think about this problem is as well to check on server side that GET and POST request are not equivalent.

A POST request can alter data in server side, a GET request mustn't change anything. That's the HTTP protocol. An IMG tag is a GET request, always. And the browser can perform this GET request without any risk, so the problem is on server side, every action that can change alter data (database, session, etc) must check the request is a POST one. For example your /post url, should return asking for a POST confirmation. If this is wrong in your application, then you'll have problems not only with altered IMG tags, but maybe as well with 'html page speeders' that make preload of GET references, or even bots.

It's possible to 'force' (rewrite) the code, but I think we should error in the way of security as it's our duty to try to protect our users as much as possible."




Sorry for any inconvenience, but site and member safety come first, as it should be.
I'm no authority, but I have plenty of anecdotal experience that suggests that it's not good practice to include spaces in any filenames, etc....and it's also not wise to make them any longer than they have to be.
Back to top
View user's profile Visit poster's website Photo Gallery
Roy_A_Lingle
Power User

Offline Offline
Joined: Jan 24, 2006
Posts: 1997
Location: El Paso & Ft Bliss, Texas
PostPosted: Tue Feb 07, 2012 10:20 pm
Post subject: Re: Page themes fixed...

Hi Doug! Hi Folks!

Thanks for the update! The last thing we all need is to lose another site.

Sgt, Scouts out!

_________________
"You can never have too much reconnaissance."
General G.S. Patton Jr.
Back to top
View user's profile Send e-mail
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ›  AFV News Discussion Board
Page 2 of 2
All times are GMT - 6 Hours
Go to page Previous  1, 2



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum