We build. You grow.

Get best community software here

Start a social network, a fan-site, an education project with oxwall - free opensource community software

Protection threat - Password Protected Photo Albums | Forum

Ilja
Ilja Dec 20 '15
Hi,


users claims that they can simply access photo in "protected" albums. Just open source code and find a link to a "locked" photo.


Is this true? If so, it must be fixed.



Skalfa LLC Partner
Skalfa LLC Jan 7 '16

Hello Ilja,


You are right, if a user browses the source of the page they will be able to see the URL of the photo. This happens because Photo plugin adds meta tags for the sharing feature which drag and show the URL of the original photo file. I have reported this to Oxwall team and we jointly will fix this issue.


Thank you for the report.

The Forum post is edited by Skalfa LLC Jan 8 '16
Lars Nilsem
Lars Nilsem Jan 17 '16
Hi.

What is status on the issue that Ilja has described. Have you soon a update that will fix this?

Skalfa LLC Partner
Skalfa LLC Jan 20 '16
Lars, we have reported this issue to Oxwall team and we do our best to solve this issue as soon as possible. However, I don't have any details or time estimate to share for now.
Anitaku
Anitaku Jan 20 '16
If a plug in is faulty or potentially harmful it shouldn't be in the store. Stick by your own rules and guidelines guys..
Skalfa LLC Partner
Skalfa LLC Jan 21 '16

Phil, the problem is not in the plugin, but in the Oxwall core. There is the meta info in the Oxwall software which grabs image URL. Unfortunately, we cannot affect this functionality from inside of our plugin. That's why we contacted Oxwall team and ask them to consider adding additional events to handle such situations. 


P.S. Basing on our experience - most of the users do not even know how to view the page source, so this problem potentially, is not so harmful, as we think. Anyway, we do our best to find a proper solution as soon as possible.


Thank you for understanding.

Ilja
Ilja Jan 21 '16
Guys, I agree with you, that it is a hole for more advanced users, though it doesn't rehabilitate it.

I also agree with Phil that it's not what buyers expect when they pay money, independently why this happens. If oxwall core doesn't allow to build secure module - then it shouldn't be built, and especially - sold.


I'm appreciate that you building plugins, keep do so. I just hope you'll resolve the problem.


What's not clear to me,  why you are referring Oxwall? Aren't Skalfa and oxwall same people ?)


Skalfa LLC Partner
Skalfa LLC Jan 21 '16

Ilja, you are right, Oxwall and Skalfa is the same people. However there are two teams which work on two different products. We distribute our plugins just like other third-party developers. It's the same if any other plugin developer from the Store faced such issue - they would have to contact Oxwall and wait till they implement this or that needed event. Unfortunately, we cannot affect Oxwall roadmap and cannot force Oxwall to update their platform just because we need some functionality implemented.  We understand the seriousness of the situation and will try to find alternative way to solve this issue. 


Thank you for the report and your patience.

Ilja
Ilja Jan 29 '16
Hello. It seems there is another hole in the plugin.

When anyone with the password add comment on the photo it becomes visible to everyone on commentor wall!

Guys... is seems there is something wrong with this plugin...
Skalfa LLC Partner
Skalfa LLC Jan 29 '16

Ilja, if by saying the "commentor wall" you mean the Newsfeed, so then - you are right, the item about comment will show up on the user's profile, but the photo will be hidden by the lock image.
Here is how we tested it:
Here are three users: user A, user B, user C.
User A uploaded a photo, and protected it by password.User B entered the password and commented on the photo.User C opened the user A's profile, he couold see the item about comment, but not a photo. (see the screenshot)Meanwhile the user A and User B can see the photo, because User A is the photo owner and the user B had entered the password.



Ilja
Ilja Jan 29 '16
Thanks, you are right. It seems, that the album was not private, but disabled through general Oxwall privacy. So wrong alarm.
Skalfa LLC Partner
Skalfa LLC Feb 1 '16
You are welcome. :)
Ilja
Ilja Mar 23 '16
Ok,  guys.  Another reported problem. 

I my case I use Profile snippets plugin by your teammate Sergey.  Pivate photo are displayed to people without any restriction there.  I understand this is not your plugin.  But it seems your plugin design of privacy does not respect any other popular plugins. So peoples photos either get unprotected or other plugins should be disabled.

You should clearly disclose that in plugin description, as this is an essential information to make a decision to buy or not to buy the plugin
Skalfa LLC Partner
Skalfa LLC Mar 23 '16

Ilja, this problem has nothing to do with our plugin. We use standard methods and provide some ours, so, if the plugin developer wants their plugin was compatible with ours, they should use the same methods. For example, PayPal plugin, if someone wants their plugin works with the PayPal plugin they should use functions and methods the plugin provides to make it work correctly. 


In your case you need to contact the Profile Snippets developer and ask them if their plugin will provide the possibility to hide photos if the album is private.


From our end, all we can do is to add to all our plugins description information about that we can guarantee that the plugin works with Oxwall core and all Oxwall/Skalfa plugins. But, we believe if you take a deeper look into how it all works - you will see that there is no need to add this additional info since it would be insufficient for customers who have no idea how it works and annoying for others.


P.S. Usually, before buying our plugins, customers contact us directly and ask the questions about the plugins' functionality or compatibility with other plugins. 

Ilja
Ilja Mar 23 '16
Ok. As you pointed out I've reported a problem there. Let's wait what's his response will be.


Regarding Disclaimer, as you know, this plugin is sensitive one. Buyers want to be safe and therefore choose to pay you (as respected developer) rather than take any free plugins from doubtful reputation developers. 


There are already 2 threats reported by me: "view source" which you point to Oxwall core team and using "Profile snippets" which you point to Sergey (also an Oxwall developer)... As you guys are also on Oxwall developers I'm really lost in understanding what is going on :)


Another problem, if the plugin doesn't provide an expected privacy level - it becomes useless. Even worse, it's complicated to uninstall it, as protected photos at that moment will become available to public which may cause very painful reputational damage for site who relied on the plugin.


You're also right, we should ask a developers developers about functionality, but I'm not sure if you would provide this information at that moment. As probably you even didn't know about privacy holes mentioned in this thread.


P.S. Please don't look at me as to a problematic client spending just 25$. I just try to help improving quality being a heavy oxwall user and getting lot's of feedback from our visitors. I hope my help will allow you to earn more cash by providing better services and quality.

Skalfa LLC Partner
Skalfa LLC Mar 23 '16

Ilja, we really appreciate your feedback and reports. We do our best to solve the issues our plugin has, but sometimes our hands are tied and we should wait for Oxwall core release or Oxwall plugins release to solve some bugs or holes.


P.S. The security hole related to the meta info has been fixed. Now, if the image is protected by password, the image is not available. 

Ilja
Ilja Mar 29 '16
OK. One more report from my side.

If someone comments on a protected photo, the photo with comment is posted on user's wall.
1. While regular users (having no access) do not see the photo, they see comments. I believe it should not be public as well.
2. Admins (or maybe moderators) can see the photo on a wall, but cannot see it in album (or when opened). Here I expect either photo is closed for admins or open in both places.

Skalfa LLC Partner
Skalfa LLC Apr 7 '16

Ilja, we've checked your report (point 2) at our demo site and everything works just fine. The photo appears for admin in the Newsfeed, also when the admin clicks on it and when the admin browses the album. Could you please provide us with the steps on how to reproduce this issue.


As for the comments - we've forwarded this to our product designers. Thank you for the suggestion.

OW-Ghost
OW-Ghost Apr 7 '16
looks like a plugin i would buy if there was option when new users join they can set if they want they avatar not shows for free members. and same with private photos they can set not show for free members option. this i see some dating sites have and it attracting people buy membership just for see her photos.


maybe have a admin option where he can set password or NOT show for FREE members or set both option.


The Forum post is edited by OW-Ghost Apr 7 '16
Oxwall Accessories
Oxwall Accessories May 18 '16
If you have an rss feed the private photos will display thru the rss feed. 


I have an rss feed that sends newly uploaded pics to our facebook page. It is displaying private photos. 

Pages: 1 2 »
You do not have permission to reply this topic