in

Shozam Community

A place to learn, share and interact with other Shozam users

Backdoor Image Theft?

Last post 12-23-2007 11:49 AM by Cowboy. 4 replies.
Page 1 of 1 (5 items)
Sort Posts: Previous Next
  • 12-18-2007 8:23 PM

    • Cowboy
    • Top 10 Contributor
    • Joined on 05-15-2007
    • Granger Township, OH
    • Posts 368
    • Points 5,795

    Backdoor Image Theft?

     I know image protection from theft is important to some and there is no way to absolutely prevent it.  Shozam offers no right click protection but someone can still capture a screenshot.

    However, does upload method or how you store your images included in the gallery offer backdoors to gain access to images?

    As usual, I was playing around with URL locations of galleries.  All of the below links have right click disabled in their galleries but yet someone can gain access to the image directories.  Once there, you can access the images to save - bypassing the right click.

    http://www.tdiebold.com/Files_1/7/

    http://www.dpcphoto.com/2/

    http://imagesbarbados.com/Images-Barbados/4/

    Not picking on any of the above. I also discovered more galleries as well where this occurs plus many where you can't gain access this way.  In checking my galleries, I can't gain access this way to any of my images.

    No idea if it is an upload problem or where the original images are stored.  I use WS_FTP Pro for upload and never store any of my images in any web folders.  All original images are stored in folders under My Documents and separate from where galleries are stored.

    Also, could it be a directory structure or type of server someone uses?

    Comments anyone?

    Cowboy

    If it ain't broke... fix it until it is!

    If you have never seen Our USMC Silent Drill Team, you need to watch it here in a one of my Shozam galleries: http://www.ohiowebs.net/usmc
    • Post Points: 35
  • 12-19-2007 4:07 PM In reply to

    Re: Backdoor Image Theft?

    Cowboy,

    Good observation; indeed some servers show "directory list view" and some don't. If directory list view is enabled, then if a user types in the directory path (into the Web browser's address field) and there is no default page there to display (i.e. index.htm, index.html, default.htm, default.html) then the server shows the entire list of files and sub-directory that are present there.

    This is a setting that most Web hosts allow users to have control of, from the host's control panel. If you want to change your settings on your server, please contact your Web host for specific steps you would need to take for your account.

    Razvan Neagu
    Shozam Web Gallery Generator
    Executive Team
    • Post Points: 20
  • 12-19-2007 5:39 PM In reply to

    • Cowboy
    • Top 10 Contributor
    • Joined on 05-15-2007
    • Granger Township, OH
    • Posts 368
    • Points 5,795

    Re: Backdoor Image Theft?

     Razvan,

    Glad I don't have the problem but it might be wise for others to check their galleries to see if they have the server problem and follow your advice.

    Also, you may want to add a notation under the Protect Tab section of your help file alerting users to the problem so they are aware of it and can take steps to further protect their images.

    Thanks for your response.  Sure it will help those that read this post.

    Cowboy
     

    If it ain't broke... fix it until it is!

    If you have never seen Our USMC Silent Drill Team, you need to watch it here in a one of my Shozam galleries: http://www.ohiowebs.net/usmc
    • Post Points: 5
  • 12-22-2007 11:40 PM In reply to

    • Tom Purse
    • Top 10 Contributor
    • Joined on 03-24-2007
    • Seattle,Washington
    • Posts 376
    • Points 5,135

    Re: Backdoor Image Theft?

     I'm assuming that you found these by going to the gallery and pulling the URL out of the URL window? I just tested mine and can't access the photos this way. I would imagine it's because my gallery is on a totally different server from my main webpage. Thanks for bringing this to everyone's attention. It's certainly something I'll keep in mind if I decide to move my gallery back to the main server. A little stumped in what option I would be looking for in the webhost control panel though.

    "welcome to my world"
    http://www.northwest-scenescapes.com
    • Post Points: 20
  • 12-23-2007 11:49 AM In reply to

    • Cowboy
    • Top 10 Contributor
    • Joined on 05-15-2007
    • Granger Township, OH
    • Posts 368
    • Points 5,795

    Re: Backdoor Image Theft?

     Tom,

    Just used the address window and  backspaced to the directory.

    In a server control panel, you most likely have a Configuration option with a choice to Protect Directories.  Because every service is different, it is best to contact support with the problem and they can point you to the way to fix it through your control panel.

    On a web site, one of the easiest ways to steal images is to look in someone's images directory because most web publishing programs will create that directory & some designers will store images there. Web savvy thiefs will use this technique with great success.

    Example: www.whateverdomainname/com/images

    If it is not protected in some way, it is very easy to get the entire directory listing and save images that way rather then look at source code and copy then paste the path to the image.  Gets around a no right click script.

    A simple way to stop listing the entire images directory if your server allows it is to put a dummy index page into the images directory.  If you really want to mess with someone's mind, put a message on the page like "You have attempted to gain access to an unauthorized directory.  Our web site protection wizard has captured your information and is forwarding it to the United States Secret Service for investigation".

    Your gallery is protected but your web site server is not.

    http://www.northwest-scenescapes.com/images/

    Fortunately, you only have one image there that is worth taking. Devil

    Fish around web sites and you will find it is quite common.  Fortunately, my server defaults to protecting directory listings.

    Happy Holidays to your family also.

    Cowboy

    If it ain't broke... fix it until it is!

    If you have never seen Our USMC Silent Drill Team, you need to watch it here in a one of my Shozam galleries: http://www.ohiowebs.net/usmc
    • Post Points: 5
Page 1 of 1 (5 items)
Copyright 2008, KOMOTION, Inc. All rights reserved.