Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: John Robinson

Might be time to consider restricting hotlinked graphics to certain domains (Photobucket, tinypic, and the like) to prevent hotlink graphic shenanigans.

Even then you could post something to tinypic that has malicious code in it. Of course, getting it to execute would be a little more problematic. :)

Still, restricting hotlinks to certain known and (relatively) trusted image hosts would knock out a percentage of attacks right there.


98 posted on 07/30/2014 11:35:09 AM PDT by Lazamataz (First we beat the Soviet Union. Then we became them.)
[ Post Reply | Private Reply | To 97 | View Replies ]


To: Lazamataz

Been a longtime consideration. I’ve never liked the hot linking and it is a source of legal contention (but then so are single-sentence excerpts and even mere links for some, absurd.) Can’t cache and serve images myself due to copyright, and whitelisting may be too cumbersome both on the user-end and maintenance. Blacklisting is an option, and coupled with an index of all external links within the HTML would allow a process to ex post facto rewrite HTML records to transform live links to dead or vv (dead being a span w/id, live being a/img with id.)


99 posted on 07/30/2014 5:41:28 PM PDT by John Robinson
[ Post Reply | Private Reply | To 98 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson