2 of 2
2
Mime type problems in 1.6.4
Posted: 22 July 2008 03:58 PM   [ Ignore ]   [ # 19 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15379
Joined  05-15-2004
tuittu - 22 July 2008 03:53 PM

Ingmar you replied to me? You mean there were updates for “better handling”? I updated my forums some days ago! As you can always see what versions or builds i run with, from my sig.

No, just a general comment.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 23 July 2008 12:48 AM   [ Ignore ]   [ # 20 ]  
Grad Student
Avatar
Rank
Total Posts:  48
Joined  03-07-2008

Newest build. 1.6.4 - 20080710

This is happening on a core version install, but I might run into this problem when I upgrade my commercial version install to 1.6.4.

On http://idioom.eu/en/souvenirs/submit/ I am letting people send me an image via a freeform. I then review the entries and post them to the site if they are ok. Would I recognize an XSS-prepared image? Do they look like a normal image or would they appear broken?

Profile
 
 
Posted: 23 July 2008 01:13 AM   [ Ignore ]   [ # 21 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15379
Joined  05-15-2004

As far as security is concerned (and XSS is obviously a big part of that) there is no difference between EE Core and the full version. Images sucessfully posted by you or one of your users would never appear broken: either EE lets you upload them, or not. As a Superadmin you are exempt from these checks anyway, and you can also turn off this behavior (although we do not recommend that). It all depends on the image. Meta data might be an issue, for example.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 23 July 2008 01:19 AM   [ Ignore ]   [ # 22 ]  
Lab Technician
Avatar
RankRankRankRank
Total Posts:  1659
Joined  06-01-2007

Yes, metas of pictures were the problem in my issue. And those again, where “wrong” because of the softaware and savingtype of images. That was only in forums tho, havent had any problems with uploading but my users dont upload nothing via SAEF.

Hope you get the things going there!

Cheers:
- Tuittu

 Signature 

Using EE Commercial 1.6.6 Build 20081114  | EE forum 2.1.1 Build 20081028 | EE MSM 1.1 Build: 20081024

Profile
 
 
Posted: 23 July 2008 01:45 AM   [ Ignore ]   [ # 23 ]  
Grad Student
Avatar
Rank
Total Posts:  48
Joined  03-07-2008
Ingmar Greil - 23 July 2008 01:13 AM

As far as security is concerned (and XSS is obviously a big part of that) there is no difference between EE Core and the full version. Images sucessfully posted by you or one of your users would never appear broken: either EE lets you upload them, or not. As a Superadmin you are exempt from these checks anyway, and you can also turn off this behavior (although we do not recommend that). It all depends on the image. Meta data might be an issue, for example.

All images that appear on the site are reviewed by me. Would I be able to see that an image a user has sent to me via the form has been tampered with? Would it appear broken?

Profile
 
 
Posted: 23 July 2008 02:31 AM   [ Ignore ]   [ # 24 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15379
Joined  05-15-2004

What exactly are you doing with the images? Uploading them yourself? They’d then get checked anyway—unless you are logged in as a Suepradmin.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 23 July 2008 02:42 AM   [ Ignore ]   [ # 25 ]  
Grad Student
Avatar
Rank
Total Posts:  48
Joined  03-07-2008

Yep, I am uploading them myself as Superadmin.

Profile
 
 
Posted: 23 July 2008 04:46 AM   [ Ignore ]   [ # 26 ]  
Grad Student
Avatar
Rank
Total Posts:  48
Joined  03-07-2008

Some more info on the image: My user says that he tried uploading two versions of the image: the first was saved for web in Photoshop and the second just saved normally in Photoshop. Both triggerd the MIME type warning.

Profile
 
 
Posted: 23 July 2008 05:46 AM   [ Ignore ]   [ # 27 ]  
Administrator
Avatar
RankRankRankRankRankRank
Total Posts:  6729
Joined  03-23-2006

Hey docflo.

Sometimes the images will appear broken, and sometimes they will appear as normal images. Are you able to email me the images in question?  Let me take a look and I’ll see what’s triggering them and see if we can come up with a solution for you here.  If you email (derek.allard@ellislab.com) please include the url to this thread so I can keep things in context.

 Signature 

DerekAllard.com - CodeIgniter, ExpressionEngine, and the World of Web Design
BambooInvoice - Open Source, CodeIgniter powered invoicing.

Profile
MSG
 
 
Posted: 23 July 2008 06:15 AM   [ Ignore ]   [ # 28 ]  
Grad Student
Avatar
Rank
Total Posts:  48
Joined  03-07-2008

Thanks! I emailed you the image in question.

Profile
 
 
Posted: 23 July 2008 01:09 PM   [ Ignore ]   [ # 29 ]  
Administrator
Avatar
RankRankRankRankRankRank
Total Posts:  6729
Joined  03-23-2006

Thanks sir.  I can immediately see what is triggering the false positive.  Sorry for the inconvenience.  We’re working on a way to reduce the number of false positive flagged, and if I come up with something that will work for you I’ll be sure to let you know.  For now though, there is no way we can let this image through without crippling the security of EE.  I’m sorry.

 Signature 

DerekAllard.com - CodeIgniter, ExpressionEngine, and the World of Web Design
BambooInvoice - Open Source, CodeIgniter powered invoicing.

Profile
MSG
 
 
Posted: 11 August 2008 05:03 PM   [ Ignore ]   [ # 30 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  103
Joined  06-03-2003

Just a “ditto” here on this issue. We’re running a production site at 1.6.3 and a dev site under 1.6.4. We SuperAdmins can upload anything under 1.6.4 but any other user group has about a 50/50 success rate with JPEG images processed either through PS or Fireworks.

The same users in the same Member Group on the production server running 1.6.3 don’t have any problems with the same images that failed on 1.6.4.

This is good to know so we don’t upgrade the production site to 1.6.4.

 Signature 

Shane Robinson - twitter.com/shane

PodCamp Hawaii, October 24-25, 2008 - http://2008.PodCampHawaii.com
http://www.barefeetstudios.com
http://www.beachwalks.tv
http://reef.beachwalks.tv

Profile
 
 
Posted: 11 August 2008 05:52 PM   [ Ignore ]   [ # 31 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  12390
Joined  04-29-2002

Shane, the newest build of 1.6.4 (20080808) has some fixes in it for XSS and images. Have you tested your dev site with the newest build?

 Signature 

Quick Reference - EE Trial Options - EE Wiki - Docs for updating a build

Profile
MSG
 
 
Posted: 11 August 2008 06:07 PM   [ Ignore ]   [ # 32 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  103
Joined  06-03-2003

Aloha Sue and thanks for the info. No we haven’t. We’re using 20080626 and will try the newest build.

 Signature 

Shane Robinson - twitter.com/shane

PodCamp Hawaii, October 24-25, 2008 - http://2008.PodCampHawaii.com
http://www.barefeetstudios.com
http://www.beachwalks.tv
http://reef.beachwalks.tv

Profile
 
 
Posted: 11 August 2008 08:17 PM   [ Ignore ]   [ # 33 ]  
Administrator
Avatar
RankRankRankRankRankRank
Total Posts:  6729
Joined  03-23-2006

Darn Shane, sorry I meant to come back and alert this thread.  Yeah, please do let me know if that fixes things up for you.

 Signature 

DerekAllard.com - CodeIgniter, ExpressionEngine, and the World of Web Design
BambooInvoice - Open Source, CodeIgniter powered invoicing.

Profile
MSG
 
 
Posted: 11 August 2008 08:32 PM   [ Ignore ]   [ # 34 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  103
Joined  06-03-2003

Thanks Derek and Sue.

Actually, I won’t be able to test this for 2 weeks. Heading to Vegas to speak at the New Media Expo followed by a side trip to Santa Fe, NM.

I’ll grab the latest build when we get back and report back here on if it worked for the client uploads.

 Signature 

Shane Robinson - twitter.com/shane

PodCamp Hawaii, October 24-25, 2008 - http://2008.PodCampHawaii.com
http://www.barefeetstudios.com
http://www.beachwalks.tv
http://reef.beachwalks.tv

Profile
 
 
Posted: 11 August 2008 09:01 PM   [ Ignore ]   [ # 35 ]  
Administrator
Avatar
RankRankRankRankRankRank
Total Posts:  6729
Joined  03-23-2006

Well, congrats on the speaking engagement.  Sounds like fun.  I’m confident we got your issue, and I’ve had at least a half dozen independent verifications, so I’m going to go ahead and mark this thread as resolved for now, but if you find it didn’t fix things up for you, just start a related thread and we’ll reopen it right away for you.

Have fun in NM.

 Signature 

DerekAllard.com - CodeIgniter, ExpressionEngine, and the World of Web Design
BambooInvoice - Open Source, CodeIgniter powered invoicing.

Profile
MSG
 
 
   
2 of 2
2
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 09:33 AM
Total Registered Members: 64933 Total Logged-in Users: 54
Total Topics: 81900 Total Anonymous Users: 28
Total Replies: 440271 Total Guests: 262
Total Posts: 522171    
Members ( View Memberlist )
Newest Members:  Kathryn DaviesPetrovichusharurblaisdellLevagstudioigotthelemonmileswkakiharaAurels