ska: unmasked interrupts
Sunday, 20. June 2010

Can you find the img src?

an image

Well, actually you can find the src of this image, but is it of any use?
Try right-click-view-the-image - I love webservers, that know what you should get.

Our Intermedia server suite analyzes the http-accept header in the request and decides what content actually goes out. Works like a charm.

... read more stories on the topic int

... permalink... comment  ...xml version of this page

 

Very useful!

This kind of processing is very useful if you want to make image stealing more complicated. I like it.

... link  

 

Well, it does prevent the "average" internet user from doing that.
But that only proves, how low the average is nowadays.

... link  

 

I think the motivation for image stealing is in most cases, that it shouldn't take to long. Of course this kind of processing is no massive obstacle for a thief.

... link  

 

Well...

curl -O "http://intermedia.pixelboxx.com/demo/metaimage/_8BE5SrQJKr3_Vv1mfOGaIHd5d/f,p/plastic_kiss_on_a_car.png"

That doesn't take much longer than right click and save and it's internet 101 level stuff.

... link  

 

Using a command-line tool like cURL is definitely something for more experienced web user and neither faster if you don't navigate with a GUI web browser (open the shell, knowledge of the tool, parameters, ...). The "101 level stuff" doesn't work here every time without some modifications, because of "http-accept".

... link  

 

Well, I even resolve to "deliver the png" when a "*/*" is preferred via accept.
So that's why CURL works without further options.
Enhancing this method by browser identification, whitelisting and such would elevate effectiveness to about 8 to 9 out of 10. Which is farely good.
And you can still src the image from another site.

... link  


... comment
 

nice

Using # as uri reference for css background is really a nice touch.

... link  


... comment

Online for 921 days
Last update: 2010.09.01, 12:35
... home
... about
... news feeds
search
 
status
You're not logged in ... login
tweets
unmasked links of interest
Anonymous Pro
Anonymous Pro (2009) is a family of four fixed-width fonts designed especially with...
Lawsuit: Disney, others spy...
Ars Technica: A flash based tracking cookie resists deletion and is aimed on kids...
Mana Bar :: Australia's First...
Australias first video game bar - Princess Peach never before looked that tempting
You're Doing It Wrong - ACM...
You're Doing It Wrong Think you've mastered the art of server performance?...
Facebook's Eroding Privacy...
To help illustrate Facebook's shift away from privacy, the Electronic Frontier...
Amazon.com: Contech Electronics...
When you listed your product on Amazon, be aware of user generated content, especially...
Improving download behaviors...
The confusing and inconsistent state of downloading files using a web browser has...
Employers: Look to gaming...
Clearly defined goals and fair, incremental rewards are two game design techniques...
Edge 313
David Gelernter: Time to start taking the internet seriously
Linguistic profiling: The...
Speakers with German accents ? even if they stumble into grammatical errors ? are...
more unmasked links...
unmasked recent updates
Nice
As I can see, my recommendation concerning ImgPro is...
by nie (2010.09.01, 12:35)
Intermedia Fotoficient...
A few things happened backstage, that involved releasing...
by ska (2010.08.31, 13:40)
...
Et voila.
by ska (2010.08.30, 17:24)
Flexible layouts
by ska (2010.08.27, 13:33)
Intermedia Fotoficient...
And while we're on it, we provided a functional facelift...
by ska (2010.08.26, 16:38)
menu
... home
... topics
... galleries

... Pixelbloxx home
calendar
June 2010
Mon
Tue
Wed
Thu
Fri
Sat
Sun
 
 1 
 2 
 3 
 4 
 5 
 6 
 7 
 8 
 9 
11
12
13
14
15
16
17
21
22
23
24
25
26
27
28
29
30
 
 
 
 
 

xml version of this page

made with antville

XING