PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > vBGallery Support > vBGallery Suggestions

vBGallery Suggestions Post your comments, suggestions, and other feedback about PhotoPost vBGallery here.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old November 8th, 2009, 03:43 AM   #1 (permalink)
Registered User
 
Join Date: Aug 2005
Posts: 1,229
[Suggestion] Always reprocess originals for security reasons

I was doing a little reading and ran into a vulnerability of images through something called Gifar.
Those are images combined with java jar files that can access your browser
Quote:
GIFARs can be files other than combined GIF+JAR files, they could also be JPG+JAR, DOC+JAR, etc.
you can do some reading by searching Gifar on google or checking last years Black Hat conference:
Black Hat Sneak Preview | Zero Day | ZDNet.com
Sun has fixed this vulnerability in java, but you dont know if your users have installed the latest java plugin for their browser...
to be 100% sure nobody uploads a gifar to your site,

In vbgallery you have 2 possibilities..

Set: Save Original Files to no...
(drawback: you loose the original
and smaller files wont be resized => keeping potential gifar danger..)

Set the Original Image Quality from -1 to something like 75
the original will then be processed and gd2 or imagemagic will create a new file without malicious code...

BUT i am not sure if in that case gif or png images are really reprocessed..
as the quality option only affects jpgs. ( reprocessing is excluded in vbgallery: AND $imageinfo['numericaltype'] != 1)

So i suggest that reprocessing of gifs is allowed and forced in next vbgallery.

I would also Suggest, that a re-size original option (with max sizes) be added to next version.. ( this has nothing to do with vulnerabilies)

Luc

PS: i thought about another way... but it looks like a memory hog.. :
read the file into a string.. search for string like ".jar" or ".class" (is usually at the end of the code). if yes, reprocess the image..

Last edited by Luciano; November 8th, 2009 at 03:48 AM.
Luciano is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Reprocess Thumbnails? shelbyforums Photopost Pro How Do I...? 2 February 8th, 2007 06:46 PM
Error: For security reasons, please remove the install.php.... woodwater Photopost Pro Installation & Upgrades 8 May 26th, 2005 10:46 AM
Security Announcement: PhotoPost Immune from EXIF PHP Security Flaw Michael P General Discussion 0 December 22nd, 2004 08:10 AM
Security ? NotInUse General Discussion 1 August 10th, 2004 11:39 PM


All times are GMT -5. The time now is 05:41 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0