Lirae.co.uk

  Skip to content?
 

OMG Updates!!!

Posted on August 18th, 2008 at 8:44pm

I actually got up off my arse for once and updated the site. :)

LWOB got quite a big update.
In June 2007, LWOB had a security scare, where it would have been possible for someone to exploit your user accounts, using a hole in the script. Unfortunately, the problem wasn't limited to my script; most button / image linking scripts (including topsite scripts and ad rotations) could also be a risk. It's up to you to use the scripts but you really must know what you could be letting yourself in for. The type of attack is called a CSRF attack^.

The good news is that I've removed the part of the script which automatically shows the user's chosen image. Instead, they give you the URL to their page full of link buttons to choose and you choose one. You can also upload the button/s within the script, as you're approving the request. :)

The upload script checks that the file type is an accepted type (jpg or gif - NO pngs!) and is less than 350kb. It also checks that the image is a valid image. If any or all of these are untrue, the image is deleted from the server. :)

Anyway, if anyone finds any errors, please let me know. My email address is mail @ lirae.net - I should be back online on Wednesday (although it'll be brief).

2 Comments on "OMG Updates!!!"...

 

Kim commented on August 19th, 2008 at 11:57am. (Permalink?)

YAY Updates!
And Little Wall 'O Buttons is back :D

 

Yvette commented on August 19th, 2008 at 1:39pm. (Permalink?)

Glad you managed to fix the security issue. And those are a lot of updates. :D

 

Comment On "OMG Updates!!!"





All new lines / line breaks are automatically converted to <br />.

 
 
 

All content is copyright © 2004-2008 Carlee Tibbs, unless stated otherwise.

Jump To The Top Of The Page