Avatars

General discussion for players of Oolite.

Moderators: winston, another_commander

Post Reply
User avatar
Alex
---- E L I T E ----
---- E L I T E ----
Posts: 770
Joined: Mon Oct 06, 2008 10:49 pm
Location: Oz. The land of some gold but mostly rust

Avatars

Post by Alex »

Hi
I'm having problems uploading an avatar.
Is there a type of file it has to be? Trying .jpg
Image is 100X72 pix
Tried doing it straight to this site and tried using host URL.
Just get the wee box with X
The image is;
Image

I must be missing something silly no doubt...

A
Screet
---- E L I T E ----
---- E L I T E ----
Posts: 1883
Joined: Wed Dec 10, 2008 3:02 am
Location: Bremen, Germany

Re: Avatars

Post by Screet »

Alex wrote:
I must be missing something silly no doubt...
AFAIK there was a problem with the BBS that hackers would use the avatar function to store illegal and undesired material, thus it had to be turned off.

Screet
User avatar
Alex
---- E L I T E ----
---- E L I T E ----
Posts: 770
Joined: Mon Oct 06, 2008 10:49 pm
Location: Oz. The land of some gold but mostly rust

Post by Alex »

Thanks Screet at least I know I.m only a wee bit silly then.
But what does AFa... as I typed it I got it.
How can someone store stuff in an avatar?
On second thought Na I don't wont to know that.

A
User avatar
Nemoricus
---- E L I T E ----
---- E L I T E ----
Posts: 388
Joined: Mon May 18, 2009 8:51 pm

Re: Avatars

Post by Nemoricus »

Screet wrote:
AFAIK there was a problem with the BBS that hackers would use the avatar function to store illegal and undesired material, thus it had to be turned off.

Screet
Then how did those people with avatars get them?
Dream as if you'll live forever
Live as if you'll die tomorrow
User avatar
DaddyHoggy
Intergalactic Spam Assassin
Intergalactic Spam Assassin
Posts: 8515
Joined: Tue Dec 05, 2006 9:43 pm
Location: Newbury, UK
Contact:

Post by DaddyHoggy »

We got'em before Ahruman had to lock that bit of the BB down.

AFAIK = As Far As I Know
Selezen wrote:
Apparently I was having a DaddyHoggy moment.
Oolite Life is now revealed here
User avatar
Diziet Sma
---- E L I T E ----
---- E L I T E ----
Posts: 6311
Joined: Mon Apr 06, 2009 12:20 pm
Location: Aboard the Pitviper S.E. "Blackwidow"

Post by Diziet Sma »

Wouldn't a sanity-check for file size and type be enough to prevent that kind of abuse? Seems to me that ought to be a standard feature of any BB software. Heck, any code I ever wrote always checked user input for validity before accepting it... and that was 20 years ago...
Most games have some sort of paddling-pool-and-water-wings beginning to ease you in: Oolite takes the rather more Darwinian approach of heaving you straight into the ocean, often with a brick or two in your pockets for luck. ~ Disembodied
User avatar
JensAyton
Grand Admiral Emeritus
Grand Admiral Emeritus
Posts: 6657
Joined: Sat Apr 02, 2005 2:43 pm
Location: Sweden
Contact:

Post by JensAyton »

Diziet Sma wrote:
Wouldn't a sanity-check for file size and type be enough to prevent that kind of abuse? Seems to me that ought to be a standard feature of any BB software. Heck, any code I ever wrote always checked user input for validity before accepting it... and that was 20 years ago...
If security and sanity were a goal, it wouldn’t be written in PHP… but I, for one, have no interest in taking on BB software as yet another side project. :-)

(Actually, come to think of it, the phpBB people blamed the problem on some other piece of software, which may or may not also be running on Giles’s server; I asked, but didn’t get a reply. File size isn’t relevant, since the problem was a small set of scripts.)
User avatar
Yodeebe
---- E L I T E ----
---- E L I T E ----
Posts: 261
Joined: Mon Oct 13, 2008 7:32 pm
Location: Namab

Post by Yodeebe »

how about setting a time when everyone can change they're avatars, then locking them again?
User avatar
Nemoricus
---- E L I T E ----
---- E L I T E ----
Posts: 388
Joined: Mon May 18, 2009 8:51 pm

Post by Nemoricus »

Yodeebe wrote:
how about setting a time when everyone can change they're avatars, then locking them again?
This would be nice.
Dream as if you'll live forever
Live as if you'll die tomorrow
User avatar
Diziet Sma
---- E L I T E ----
---- E L I T E ----
Posts: 6311
Joined: Mon Apr 06, 2009 12:20 pm
Location: Aboard the Pitviper S.E. "Blackwidow"

Post by Diziet Sma »

What about enabling THIS option in the phpBB settings?

Image
Another forum I hang out on which also uses phpBB allows you to link to an avatar stored offsite.. it seems to me this would solve the problem in a way that's of no use to hackers.
Most games have some sort of paddling-pool-and-water-wings beginning to ease you in: Oolite takes the rather more Darwinian approach of heaving you straight into the ocean, often with a brick or two in your pockets for luck. ~ Disembodied
User avatar
Cmd. Cheyd
---- E L I T E ----
---- E L I T E ----
Posts: 934
Joined: Tue Dec 16, 2008 2:52 pm
Location: Deep Horizon Industries Manufacturing & Research Site somewhere in G8...

Post by Cmd. Cheyd »

Actually it is...

I'm a malicious hacker. I create a JPG or other image that has known exploits, and include the exploit. I host it via Flickr, Photobucket, or Bill & Ted's Excellent Photo Hosting Service. I set this as my Avatar. And I start posting all over the forums....
User avatar
Nemoricus
---- E L I T E ----
---- E L I T E ----
Posts: 388
Joined: Mon May 18, 2009 8:51 pm

Post by Nemoricus »

Unfortunately, that makes a lot of sense.

Also, I discovered that this forum has a set of avatars already uploaded. That's where my current, very nice one comes from. Is it possible that we could submit avatars of a similar style to the admins for approval and have them added to the list?
Dream as if you'll live forever
Live as if you'll die tomorrow
User avatar
Diziet Sma
---- E L I T E ----
---- E L I T E ----
Posts: 6311
Joined: Mon Apr 06, 2009 12:20 pm
Location: Aboard the Pitviper S.E. "Blackwidow"

Post by Diziet Sma »

Nemoricus wrote:
Unfortunately, that makes a lot of sense.
Yes, sadly, I have to agree..
Nemoricus wrote:
Also, I discovered that this forum has a set of avatars already uploaded. That's where my current, very nice one comes from. Is it possible that we could submit avatars of a similar style to the admins for approval and have them added to the list?
This would work for me... :D
Most games have some sort of paddling-pool-and-water-wings beginning to ease you in: Oolite takes the rather more Darwinian approach of heaving you straight into the ocean, often with a brick or two in your pockets for luck. ~ Disembodied
User avatar
saint
Dangerous
Dangerous
Posts: 75
Joined: Fri Jul 24, 2009 5:17 pm
Location: 45.371747 N, 12.011885 E - Sol III
Contact:

Post by saint »

Alex wrote:
How can someone store stuff in an avatar?
<tech>
When a programmer fails to write the required checks :>, a bunch of malicious data can be used to overvride (almost)wildly a memory area succeeding in getting some evil code executed, it's a bit of wizardry that
requires to know low level computer programming.

BTW, Apple iPhones an iPod Touch where jailbroken this way...
</tech>

Sniff, I miss Eastern Gianozia People Republic Ltd. crest ); ... :)
Image
Cmdr. Saint, Golden Gladstone with 4 leaves Clovers of the Most Noble Order or The B.D.c.
Post Reply