Page Index Toggle Pages: 1 ... 3 4 [5] 6  Send TopicPrint
Very Hot Topic (More than 25 Replies) Stealth Email Addresses V1.0a SP1.3.x (Read 40426 times)
Valtiel
God Member
*****
Offline


Copy & paste coder

Posts: 873
Joined: Sep 5th, 2003
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #60 - Sep 18th, 2004 at 12:11pm
Print Post  
Yeah, it surely cuts a fine figure  Grin
  

Proud copy & paste coder Grin
Admin @ Silent Hill Forum
Back to top
WWW  
IP Logged
 
thecaretaker
Junior Member
**
Offline


I am thecaretaker

Posts: 87
Location: 1066 Country
Joined: Dec 5th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #61 - Sep 28th, 2004 at 9:54am
Print Post  
Hello Ron,

Great mod and seems to be working fine on my forum. I do have a question for you though. Maybe you can put my mind to rest.

I notice when looking at the members .dat files, the email address of my members is not encrypted or slit up in any way. I have added a no robots script to keep bots out of my cgi-bin, but I understand this only works for honest robots and not the rouges. Does Yabb have any system/mechanism to prevent the exposure of email addresses in the members files?

If it does, I'll be very pleased (and maybe you could give a brief description of how it works). However, if it does not, maybe it would be a good idea to add something like encryption or splitting the address up into different files in the next version so that bots can't grab addresses.

Just a thought! Wink
  

Growing old is mandatory. Growing up is optional!
Back to top
WWW  
IP Logged
 
Valtiel
God Member
*****
Offline


Copy & paste coder

Posts: 873
Joined: Sep 5th, 2003
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #62 - Sep 28th, 2004 at 10:09am
Print Post  
Hm, how should bots have access to the cgi-bin folder? Normally it's protected from server side and/or .htaccess files so you can't call it from browsers or similar.
  

Proud copy & paste coder Grin
Admin @ Silent Hill Forum
Back to top
WWW  
IP Logged
 
thecaretaker
Junior Member
**
Offline


I am thecaretaker

Posts: 87
Location: 1066 Country
Joined: Dec 5th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #63 - Sep 28th, 2004 at 10:43am
Print Post  
To be honest, I don't know how these web bots work. I'm happy if this is the case. Prolly explains why my forum posts don't show up in Google then Wink

I get a bit paranoid about security Wink

Thanks for the info!
  

Growing old is mandatory. Growing up is optional!
Back to top
WWW  
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #64 - Sep 28th, 2004 at 11:38am
Print Post  
thecaretaker wrote on Sep 28th, 2004 at 9:54am:
Hello Ron,

Great mod and seems to be working fine on my forum. I do have a question for you though. Maybe you can put my mind to rest.

I notice when looking at the members .dat files, the email address of my members is not encrypted or slit up in any way. I have added a no robots script to keep bots out of my cgi-bin, but I understand this only works for honest robots and not the rouges. Does Yabb have any system/mechanism to prevent the exposure of email addresses in the members files?

If it does, I'll be very pleased (and maybe you could give a brief description of how it works). However, if it does not, maybe it would be a good idea to add something like encryption or splitting the address up into different files in the next version so that bots can't grab addresses.

Just a thought! Wink

As Valtiel wrote, on any nix based webserver the /Members dir is protected by the .htaccess file not allowing bots or anyone else but the mainscript in.
On IIS and some Windows server there are separate measures you have to take to protect the .dat files.

Simplest test to see if your datfiles are secure is to try and call one up through your browser like http://www.yourdomain.com/cgi-bin/yabb/Members/admin.dat
If you get a 403 error or any other access denied or file not found error you can be pretty sure that if you can't get it so can't the bots.
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
Valtiel
God Member
*****
Offline


Copy & paste coder

Posts: 873
Joined: Sep 5th, 2003
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #65 - Sep 28th, 2004 at 11:39am
Print Post  
@thecaretaker:
Well, the normal search engine bots have the same rights than any browsers do. They can only follow those links which are shown on your page. For example if you close your board or single forums for guest, also bots cannot "see" them anymore.

And they also aren't able to go into your cgi-bin and browse your .dat files Wink

That's all for normal bots. There might be "evil" bots which have other abilities. I don't know about that.

But for the normal bots the method how Ron "encrypts" mail addresses works fine as the mail links are stealthed and the bots can only index the stealthed links which aren't useful for them to collect any mail addresses.
  

Proud copy & paste coder Grin
Admin @ Silent Hill Forum
Back to top
WWW  
IP Logged
 
thecaretaker
Junior Member
**
Offline


I am thecaretaker

Posts: 87
Location: 1066 Country
Joined: Dec 5th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #66 - Sep 28th, 2004 at 12:25pm
Print Post  
I'm with it now. Many thanks to both of you for explaining it. I did the check Ron and I got 'Forbidden' you do not have permission to access this file.

Cheers again! Wink
  

Growing old is mandatory. Growing up is optional!
Back to top
WWW  
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #67 - Sep 28th, 2004 at 2:02pm
Print Post  
thecaretaker wrote on Sep 28th, 2004 at 12:25pm:
I'm with it now. Many thanks to both of you for explaining it. I did the check Ron and I got 'Forbidden' you do not have permission to access this file.

Cheers again! Wink

You're most welcome, enjoy the mod Grin
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
thecaretaker
Junior Member
**
Offline


I am thecaretaker

Posts: 87
Location: 1066 Country
Joined: Dec 5th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #68 - Oct 5th, 2004 at 7:12pm
Print Post  
Hello Ron. I found a rare but annoying glitch. Some addresses show up as .co.DJ or .co.uJ instead of .co.uk.

Would an email address that had more than 2 full stops be a problem? I have a user with office @ name.essex.sch.uk and it replaces the uk with DJ

It only happens for a very few user addresses, most are fine and the addresses it happens to only seem to have normal charaters/numbers (no minuses or under scores).

I've removed the mod for a while in hope you might have an idea why this happens. I don't have YAMS and I did upload the latest version.
  

Growing old is mandatory. Growing up is optional!
Back to top
WWW  
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #69 - Oct 5th, 2004 at 8:30pm
Print Post  
thecaretaker wrote on Oct 5th, 2004 at 7:12pm:
Hello Ron. I found a rare but annoying glitch. Some addresses show up as .co.DJ or .co.uJ instead of .co.uk.

Would an email address that had more than 2 full stops be a problem? I have a user with office @ name.essex.sch.uk and it replaces the uk with DJ

It only happens for a very few user addresses, most are fine and the addresses it happens to only seem to have normal charaters/numbers (no minuses or under scores).

I've removed the mod for a while in hope you might have an idea why this happens. I don't have YAMS and I did upload the latest version.

That's strange, I'll look into that one Wink
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
thecaretaker
Junior Member
**
Offline


I am thecaretaker

Posts: 87
Location: 1066 Country
Joined: Dec 5th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #70 - Oct 5th, 2004 at 8:46pm
Print Post  
It was the same in both profile and memberlist if that makes any difference. Thanks Ron for looking at it for me. Your a star!
  

Growing old is mandatory. Growing up is optional!
Back to top
WWW  
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #71 - Oct 5th, 2004 at 8:50pm
Print Post  
thecaretaker wrote on Oct 5th, 2004 at 8:46pm:
It was the same in both profile and memberlist if that makes any difference. Thanks Ron for looking at it for me. Your a star!

The same en/decryption is used throughout the mod so if it screws up once it does so everywhere.
Working on it Wink
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #72 - Oct 5th, 2004 at 9:07pm
Print Post  
Mmmm, can't reproduce it with office@name.essex.sch.uk on my board, can you give me a link to your board so I can see what happens ?
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
Kong
God Member
*****
Offline


Is it just me or is my
back hairy???

Posts: 858
Joined: Aug 2nd, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #73 - Feb 11th, 2005 at 12:19am
Print Post  
Stealth Email Addresses V1.0a SP1.3.x

Is this the latest version?
Did it ever go beyond this or out of Beta?

I dont' see it anything else anywhere so I thought I would ask. Smiley
  


Back to top
 
IP Logged
 
Spikecity
God Member
*****
Offline


Beer anyone ?

Posts: 2630
Location: New York
Joined: Apr 16th, 2002
Gender: Male
Re: Stealth Email Addresses V1.0a SP1.3.x
Reply #74 - Feb 11th, 2005 at 1:38pm
Print Post  
This is the last version and should be taken to the final versions and into the database.
  

Nothing to add here Smiley
Back to top
 
IP Logged
 
Page Index Toggle Pages: 1 ... 3 4 [5] 6 
Send TopicPrint