Author

Topic: Avata (Read 1072 times)

global moderator
Activity: 3990
Merit: 2713
Join the world-leading crypto sportsbook NOW!
November 14, 2014, 07:57:37 AM
#7
When we will be able to use avatars again they should be available to only high status members I think. Hero and up.

Why? I can understand disallowing Newbs to have them to limit impersonation, but limiting it to Hero seems a bit extreme.

So avatars are used to hack the forum. But I'm wondering how?

If you allow users to just upload .jpg files with certain dimensions, nothing will happen I guess.

I don't know the full details but I think malicious code was uploaded or implemented somehow.
legendary
Activity: 2170
Merit: 1427
November 14, 2014, 07:43:55 AM
#6
So avatars are used to hack the forum. But I'm wondering how?

If you allow users to just upload .jpg files with certain dimensions, nothing will happen I guess.
legendary
Activity: 1596
Merit: 1005
★Nitrogensports.eu★
November 14, 2014, 07:10:56 AM
#5
When we will be able to use avatars again they should be available to only high status members I think. Hero and up.
sr. member
Activity: 309
Merit: 250
November 13, 2014, 07:15:19 AM
#4
as far as I know , a new version of the forum (update) will be available on February 2015 . and avatars will be available
but not sure , since we skipped the beta test date  Huh
hero member
Activity: 508
Merit: 500
Techwolf on #bitcoin and Reddit
November 13, 2014, 12:41:54 AM
#3
To quote myself from the last time this came up (yes, it's been asked at least this many times; there are currently two Meta threads asking this same question, even):

Any progress?

Please turn off this forum! The avatars are the only advantage over a mailing list. This is bitter but true. Give something better a chance. Give up!

I'm pretty sure that avatars will be disabled until at least the new forum is out and being used - as theymos has stated it was removed due to an exploit made possible by avatars and though I believe the exploit has been patched he is not keen on restoring the functionality.

From what I've heard, pretty much. The exploit involved uploading a php script instead of an image into an executable directory, then using it to put some (slightly) malicious Javascript into the forum's MOTD so that it ran on every page. I followed the troubleshooting and analysis through IRC while it was being fixed immediately after the hack, but it seems that avatars may be disabled for a while anyway.

Though the exploit used has been patched, it's been long enough that I suspect new avatars may remain disabled until the new forum software is put into place, but those who had them before the hack like me were able to keep them (though we can't change our avatars either).

Official response on the ETA of the new forum:

Q: Why doesn't the forum let me add an avatar?
A: The forum was hacked some time ago. It is thought that the avatars were used as a means of injecting malicious code into the forum. Even though the vulnerability was patched, the avatars will be disabled until a new forum software is released.

Q: So when is the new forum software coming?
A: Well, according to theymos, some time after February 2015.

<...>
Quote
When will the software be finished?

About one year from now.
<...>
full member
Activity: 197
Merit: 100
November 11, 2014, 12:36:25 AM
#2
If by 'avata' you mean "Avatar" or the picture next to some people's username, then they were partially disabled when the forum got hacked last year (the ability to change/add avatars was disabled).

When the new forum goes live sometime early next year avatars will be re-enabled again
newbie
Activity: 17
Merit: 0
November 11, 2014, 12:11:08 AM
#1
title how long forum will open use avata here ?
Jump to: