English Amiga Board


Go Back   English Amiga Board > abime.net - Hall Of Light > HOL suggestions and feedback

 
 
Thread Tools
Old 12 December 2004, 17:58   #1
silkworm
Zone Friend
 
silkworm's Avatar
 
Join Date: Oct 2004
Location: United Kingdom
Posts: 221
Unhappy Problems with HOL 2 arghh! help please

ever since you've updated i can't view any pictures.

i've tried in each browser and still the same result, i've included pics so you can see what i mean, in ie there are just crosses while firefox show nowt

i've disabled the firewall, and all add blocking in firefox etc and its still the same, it all worked perfectly before the update.

I havent noticed this problem on any other sites, i've tried everything, i just don't know what to do, can anyone help ????

bloody computer, its driving me mad
as usual i bet its only me who is having problems



silkworm is offline  
Old 12 December 2004, 18:08   #2
jmmijo
Junior Member
 
jmmijo's Avatar
 
Join Date: Jan 2002
Location: PDX
Age: 62
Posts: 2,395
It's working for me Silkworm, I use an IE clone called Maxthon and all the screenies show up just fine. I even viewed A-10 Tank Killer like your shots show

Have you tried clearing your Temp Internet Cache folders yet ?!?
jmmijo is offline  
Old 12 December 2004, 18:38   #3
IFW
Moderator
 
IFW's Avatar
 
Join Date: Jan 2003
Location: ...
Age: 52
Posts: 1,838
It's because cookies and/or referrers are disabled. Enable them for hol's address.
IFW is offline  
Old 12 December 2004, 19:10   #4
silkworm
Zone Friend
 
silkworm's Avatar
 
Join Date: Oct 2004
Location: United Kingdom
Posts: 221
Quote:
Originally Posted by IFW
It's because cookies and/or referrers are disabled. Enable them for hol's address.
damn it, you're right, i thought i'd done the cookies thing, after all that it was the poxy cookies. God how i hate windows shite, and all this firewall, spywear blocking, browser hijacking crap, it aint like it used to be

anyway thanks for replying chaps.

btw the new HOL looks ace
silkworm is offline  
Old 12 December 2004, 19:25   #5
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
yes, temp cookie are needed to maintain the HOL session.
Thanks for the quick response IFW
RCK is offline  
Old 13 December 2004, 00:45   #6
andreas
Zone Friend
 
Join Date: Jun 2001
Location: Germany
Age: 50
Posts: 5,857
Send a message via ICQ to andreas Send a message via AIM to andreas
Question

What's so essential about those temp cookies that they're so absolutely needed?
What functionality would be missed in HOL when there would be no temp cookies used at all?
andreas is offline  
Old 13 December 2004, 12:11   #7
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
no session cookies = no server session
no server session = no hol2
RCK is offline  
Old 13 December 2004, 13:07   #8
derSammler
Senior Member
 
Join Date: Jun 2001
Location: Germany
Posts: 1,645
I don't like cookies as well. Can't you just attach the session id to the url ?
derSammler is offline  
Old 13 December 2004, 13:28   #9
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
permanent cookie are needed to save your user preferences.
temporary cookie are needed to save your session informations.
PHP will auto parse session ID in URL if your browser doesn't support temporary cookie.
RCK is offline  
Old 13 December 2004, 21:45   #10
Mr Creosote
Evil Mastermind
 
Mr Creosote's Avatar
 
Join Date: Jul 2002
Location: Home
Posts: 740
Quote:
Originally Posted by RCK
PHP will auto parse session ID in URL if your browser doesn't support temporary cookie.
Don't know, but it doesn't for me. No session information is passed by URL, no images are shown.
Mr Creosote is offline  
Old 13 December 2004, 22:10   #11
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
I though PHP comportment was that, but it fact, it does not parse SID automatically by default.
Passing SID via URL is one security hole, I won't implement it.

Anyway, I have added a script on the homepage which will tell you is your current browser will work with HOL. If not, simply update to "yes" your per-session cookies parameters.
RCK is offline  
Old 15 December 2004, 07:36   #12
andreas
Zone Friend
 
Join Date: Jun 2001
Location: Germany
Age: 50
Posts: 5,857
Send a message via ICQ to andreas Send a message via AIM to andreas
Quote:
Originally Posted by RCK
I though PHP comportment was that, but it fact, it does not parse SID automatically by default.
Passing SID via URL is one security hole, I won't implement it.
Security hole?
What mischief can be done with a mere *session* ID given by the URL?
I don't get that part.
andreas is offline  
Old 15 December 2004, 13:58   #13
derSammler
Senior Member
 
Join Date: Jun 2001
Location: Germany
Posts: 1,645
Someone could steal the admin session for example. But I don't think this is really a security hole. By default a session gets invalid after one hour, so it's rather safe.
derSammler is offline  
Old 15 December 2004, 15:23   #14
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
Quote:
Originally Posted by andreas
Security hole?
What mischief can be done with a mere *session* ID given by the URL?
I don't get that part.
I will explain you this over IRC
Anyway I won't change from point of view
RCK is offline  
Old 15 December 2004, 19:05   #15
andreas
Zone Friend
 
Join Date: Jun 2001
Location: Germany
Age: 50
Posts: 5,857
Send a message via ICQ to andreas Send a message via AIM to andreas
Thumbs down No, I can't agree here.

Your decision. But frankly, I find it very silly to insist on cookies so stubbornly if so many people have disabled them by default.
And if WindowsKiller - who himself was admin for a decently long period - affirms that it's *no* security hole and of mere marginal importance regarding security, you can safely believe him.
HOL does always have to be very special and thus always requires special treatment, eh?
Maybe overthink your viewpoint again.

My 2 cents.

Last edited by andreas; 15 December 2004 at 21:04.
andreas is offline  
Old 15 December 2004, 19:27   #16
Jim
 
Posts: n/a
Whilst I understand the security issues this is HOL2, not HSBC
 
Old 15 December 2004, 21:13   #17
Codetapper
2 contact me: email only!
 
Codetapper's Avatar
 
Join Date: May 2001
Location: Auckland / New Zealand
Posts: 3,182
Lots of sites will simply not work without cookies, so I don't understand the big deal. Who disables cookies?

All ASP sites maintain a session using cookies, so presumably if you disable cookies you cannot view any ASP site either.
Codetapper is offline  
Old 15 December 2004, 21:15   #18
andreas
Zone Friend
 
Join Date: Jun 2001
Location: Germany
Age: 50
Posts: 5,857
Send a message via ICQ to andreas Send a message via AIM to andreas
Quote:
Originally Posted by RCK
I will explain you this over IRC
OK, RCK has now explained the reason why he does that and now I even understand why.
andreas is offline  
Old 15 December 2004, 21:28   #19
RCK
Administrator
 
RCK's Avatar
 
Join Date: Feb 2001
Location: Paris / France
Age: 45
Posts: 3,084
I will resume and conclude the situation:

We had too much leeching with the HOL1 engine.
So to have less bandwitch invoices to paid, I implemented a new protection system against leechers, based on sessions and other secret codez.
To make this working correctly without bringing the session ID into the URL (hackable), you have to use your per-session cookies browser feature.
The per-session cookies are NOT regular cookies, they will just store some temporary informations during the time you are using the website. Those kind of cookies are even stored in ram and/or deleted once your browser is closed.

note: If your browser doesn't allow per-session cookies, you will see a warning on the HOL2 homepage.

Thread closed
RCK is offline  
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Similar Threads
Thread Thread Starter Forum Replies Last Post
KG's HOL problems (Ongoing) killergorilla HOL data problems 102 24 April 2011 12:34
CyberGraphx arghh xc8 support.Other 13 23 December 2010 20:58
Serial link...arghh! quantum112 support.Hardware 84 15 July 2009 13:35
Check this out! (Ebay arghh) Heavyweight7t6 MarketPlace 17 16 June 2006 13:02

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 21:18.

Top

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Page generated in 0.09826 seconds with 13 queries