Limits Up
Welcome, Guest. Please login or register.
September 07, 2008, 12:09:03 AM

Pages: [1]
Print
Author Topic: PROBLEM : Photos are copied from user's profiles on our websites very easily  (Read 139 times)
Zeusss
Newbie
*
Posts: 18


« on: June 25, 2008, 01:51:47 PM »

Hi,

Is it normal that any user on our website can go in a user’s profile and copy the photos that are in that profile and keep them on their desktop in their computer Huh…I’ll explain how this is done and you’ll see that it’s very easy…We tested it after one of our users advised us…

All a user has to do is access another user’s profile ( go IN the profile ), click on a photo with the left button of his computer mouse and drag the chosen photo on their desktop…A file will appear on their desktop and then they open the file and the photo appears copied…Users who do this can then use the copied photo as they wish…

Admins, Try this on your websites…We visited and tested a few other websites who have the skadate module and with no problem whatsoever copied photos from  user profiles as explained higher…We even tested this with the skadate Demo…Of course we deleted those photos afterwards BUT a user who has bad intentions can keep them in his computer and do what he wants with them…I don’t think this is normal for security reasons…Users upload photos on our websites thinking they are safe and they are NOT !

We visited and tested other websites who are NOT clients of skadate ( who have other modules then skadate ) and yes you can drag and drop a photo from profiles as explained higher BUT when we open the file on the desktop, all that appears on some websites we visited is the front page of their website where we have to write our username and password AND NOT THE PHOTO and on other websites all that appears is a blank page…This is how it should be…

We work with skadate to have better security for the users by eliminating security flaws…What we just discovered should be corrected as soon as possible and this without waiting for the next version…The integrity of our website is very important to us and this is something that could ruin it…I don’t think anyone wants that for their website ??

Thanks,

Zeusss
« Last Edit: June 25, 2008, 02:14:22 PM by Zeusss » Logged
brusselsshrek
Full Member
***
Posts: 213



« Reply #1 on: June 26, 2008, 05:35:56 AM »

I don't see any security flaw.

If you can look at a web page, you can copy the photos to your system.  Period.  There's nothing ANY website can do to stop this, since it's part of the design of the web - a webpage, including all photos, is sent to a person's PC. 

Sure there are things which sites can do to stop ignorant users (e.g. disable right-button click), but this doesn't stop a user with even a simple knowledge of how web pages work.
Logged

http://romeobox.com - RomeoBox dating site
lcoover
Newbie
*
Posts: 27



« Reply #2 on: June 26, 2008, 06:52:45 AM »

Maybe take a look at this link for bots but the best security is to use watermarks across the image.

http://www.phpclasses.org/browse/package/1339.html

Logged
lcoover
Newbie
*
Posts: 27



« Reply #3 on: June 26, 2008, 06:58:15 AM »

One more good blog...best of luck...best just to watermark I think...

http://answers.yahoo.com/question/index?qid=20080512205940AACVASO
Logged
Swingnfun.com
Newbie
*
Posts: 23


« Reply #4 on: June 26, 2008, 10:40:12 AM »

Try this on my site www.swingnfun.com see if you think this is the fix your looking for?
Logged
Scallywags
Full Member
***
Posts: 186



« Reply #5 on: July 07, 2008, 12:41:25 PM »

Hi,

We are hosted and had right click disabled for us ...  however no real way around it ... you can still do a screen grab and then you got free software like screen-hunter etc .... Pics on websites can ALWAYS be copied as can the video snipets people post  even if they are flagged as non-shareable and the embed code is not shown ....

The only real way is to have a dirty great big watermark running thru the image and that sorta defeats the whole point ....

 Cool
Logged

www.swinging-scallywags.co.uk
Swinging Scallywags
The web site for Genuine UK Couples
(we a FREE Non Commercial site)

Feeling Sexy Lingerie - From Hustler & Dreamgirl
www.feelingsexylingerie.co.uk
Pages: [1]
Print
Jump to:  

You are here: Skalfa » Support » Discussion Boards