Author Topic: Be careful, image hotlinking is dangerous  (Read 201 times)

psychexplorer

  • Subordinate Wasp
  • ***
  • Posts: 138
Be careful, image hotlinking is dangerous
« on: January 20, 2011, 11:02:57 PM »
For those of you who may not know, standard forum image tags [IMG ] and [/IMG ] directly embed an external image from an external server in a thread.

When your browser loads that image as part of the thread, it will make a request to an outside server, sending along your IP, useragent, and (if not disabled and not on SSL), the referring URL. This can leak a trove of information dangerous to those not using a Tor bundle, especially if the image has been crafted by an infiltrator and is unique to one specific watched thread.

I was horrified to see images hotlinked from .gov servers in threads.

With our civil liberties on the decline every day, and obnoxious information warehousing and cross-correlation growing, it's easy to do the right thing. Use attachments, and set your browser to block third party images from external sites when viewing anything not approved by the upright morals brigade.

Advertisers have been using "beacon images" for over a decade. A beacon image is an image which, whether with or without content (although they're typically 1x1 and clear), is used to record the IP addresses and useragents of all browsers accessing a certain URL.

Forum attachments are safe. A forum attachment uses the forum's hosting, and keeps the forum as a safe intermediary between users.

Vesp

  • Administrator
  • Foundress Queen
  • *****
  • Posts: 3,130
Re: Be careful, image hotlinking is dangerous
« Reply #1 on: January 21, 2011, 04:47:26 AM »
While it is to the best of my knowledge there is no foul play going on, the rules do state:

Quote
Do not make active URLs specifically to government, journal, or publishing sites
- http://127.0.0.1/talk/index.php/topic,369.0.html

Images would count for this - if you see any .gov urls, feel free to report them.
Additionally, The Vespiary forum does this:
http://127.0.0.1/talk/index.php/topic,1062.msg15802.html#msg15802

Thanks for the info, btw
Bitcoin address: 1FVrHdXJBr6Z9uhtiQKy4g7c7yHtGKjyLy

Assyl Fartrate

  • Subordinate Wasp
  • ***
  • Posts: 229
Re: Be careful, image hotlinking is dangerous
« Reply #2 on: November 17, 2011, 06:46:21 AM »
Maybe hotlinking should be disabled entirely... it's not that inconvenient to copy and paste a URL. It will never be safe to hotlink to ANY site outside of this one. Most are too lazy to use proxies and the fewer people that know the IPs of members, the better.
Someone Who Is Me

Wizard X

  • Lord of the Realms
  • Foundress Queen
  • *****
  • Posts: 1,224
Re: Be careful, image hotlinking is dangerous
« Reply #3 on: November 17, 2011, 10:53:21 PM »
Maybe hotlinking should be disabled entirely... it's not that inconvenient to copy and paste a URL. It will never be safe to hotlink to ANY site outside of this one. Most are too lazy to use proxies and the fewer people that know the IPs of members, the better.

To see what your browser User Agent outputs, go here: http://whatsmyuseragent.com/  Switching Browser User Agents: http://whatsmyuseragent.com/SwitchingUserAgents.asp

Changing User Agent in Firefox manually. http://johnbokma.com/mexit/2004/04/24/changinguseragent.html

Another good site to test your browsers output: http://browserspy.dk/useragent.php

If I recall correctly, Vesp modified the forums script for hotlinks to show the www.thevespiary.org IP?? Vesp can you elaborate?
« Last Edit: November 17, 2011, 11:26:45 PM by Wizard X »
Albert Einstein - "Great ideas often receive violent opposition from mediocre minds."

Vesp

  • Administrator
  • Foundress Queen
  • *****
  • Posts: 3,130
Re: Be careful, image hotlinking is dangerous
« Reply #4 on: November 17, 2011, 11:57:34 PM »
"If I recall correctly, Vesp modified the forums script for hotlinks to show the www.thevespiary.org IP?? Vesp can you elaborate?"

What you are referring to is I made it so links clicked on this site do not show thevespiary.org as being the referral site. akcom wrote the script and more info on it can be found in the site matters section of this site.
Bitcoin address: 1FVrHdXJBr6Z9uhtiQKy4g7c7yHtGKjyLy

Assyl Fartrate

  • Subordinate Wasp
  • ***
  • Posts: 229
Re: Be careful, image hotlinking is dangerous
« Reply #5 on: November 18, 2011, 12:36:37 AM »
Fantastic - you've thought this through.
Someone Who Is Me

Vesp

  • Administrator
  • Foundress Queen
  • *****
  • Posts: 3,130
Re: Be careful, image hotlinking is dangerous
« Reply #6 on: November 18, 2011, 01:01:11 AM »
I think it would still show IP addresses... what I did is different I do believe.

There is a lot I need to do, but I'm not an expert when it comes to the technical stuff. I  ask for help and implement stuff that I know how to do, however.
Bitcoin address: 1FVrHdXJBr6Z9uhtiQKy4g7c7yHtGKjyLy

Assyl Fartrate

  • Subordinate Wasp
  • ***
  • Posts: 229
Re: Be careful, image hotlinking is dangerous
« Reply #7 on: November 18, 2011, 01:57:09 AM »
It's good enough. No matter what, when you load a page, it's inevitable they'll get your IP address. What's scary is when people's IP addresses end up associated with a site like this.
Someone Who Is Me