Login
Sign Up


You are using the mobile version of the forum, some features have been disabled to have it responsive.
Limelight Reunion 2024 - v4b1Limelight Discord
Ares Defence Services Discord
Limelight Reunion 2024 - v4b1Limelight DiscordAres Defence Services Discord

receiptDevelopment Blog:

Development Contributor Workflow

receiptHR Blog:

What *are* they doing over there?

receiptTeacher Blog:

Insight into the Teacher Team

receiptDevelopment Blog:

Infrastructure Upgrade 11/2019

receiptDevelopment Blog:

how suggestions???

receiptDevelopment Blog:

Planning for the future.


This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

[SECURITY] Measures against ip-loggers
Burnett radio_button_checked
Security Officer, CityRP2 Core Developer
Developer
Posts: 3,225
Threads: 201
Likes Given: 1419
Likes Recieved: 3280 in 973 posts
Joined: Aug 2015
Reputation: 45
#1
Aug 31, 2016, 01:58 PM
Good day community.

Today we have forced the forums into a new level of security. Due to recent events, you can no longer post images from foreign-untrusted sources. Malicious images can be used as a backdoor ip-logger, thus our forums will only allow trusted images.

If your signature, remote-avatar or forum-post contains an untrusted image, it will not be loaded.

So make sure to only use a trusted hoster for images.

Since we have carefully checked all image-hosters used on this forums, you shouldn't notice any issues.

Trusted hosters:
  • Discord (discordapp.com, discord.com, discord.gg)
  • Steam (steamuserimages...akamai, steamstatic.com, steampowered.com, steamcommunity.com, steamusercontent.com)
  • ts3index.com
  • Print Screen (prnt.sc, prntscr.com)
  • Dropbox (dropboxusercontent.com, dropbox.com, dropboxstatic.com)
  • vgy.me
  • puu.sh
  • photobucket.com
  • pinimg.com
  • tinypic.com
  • gravatar.com
  • tumblr.com
  • screenshot.net
  • aulod.com
  • cloudflare.com
  • imgur.com
  • giphy.com
  • wikimedia.org
  • gametracker.com
  • gyazo.com
  • speedtest.net


Want another one added? Feel free to suggest it below.

In addtion, we coded a link watcher.

Introducing the Limelight - Link watcher

[Image: 714rm03.png]

As with our image protection, non-trusted links will fire up a notice when you click on them.
An attacker could easily manipulate a link to have you forwarded to an ip-logger/bad site.

For example:

https://limelightgaming.net/forums/thread-12097

Now click on that link above and you will understand.

As you can see, links can be manipulated by adding a tittle on 'em.

While this is still possible, you will receive a notification and the real URL is printed.
It is up to you whether you enter that site or not.

Currently only *.limelightgaming.net is whitelisted to skip the notification. We might expand on this in the future. For now better be safe than sorry.


Please note:  We cannot protect you at 100%. Simply don't click on a link that might be masked as short-url.

Especially links such as goo.gl are used to redirect you to an ip-logger
If you have questions regarding Limelight Gaming's security, infrastructure or backend related topics,
feel free to contact me directly via Discord or PM.
Please note that confidential information cannot be disclosed.

Burnett
(This post was last modified: Oct 9, 2020, 12:22 PM by Doctor Internet. Edited 3 times in total.)
connbob radio_button_checked
Member
Membership
Posts: 55
Threads: 8
Likes Given: 3
Likes Recieved: 31 in 22 posts
Joined: Aug 2015
Reputation: 0
#2
Aug 31, 2016, 02:17 PM
Sounds good but what about puu.sh? I use that for my screenshotting and I know quite a few others do aswell
The following 1 user Likes connbob's post:
  • Burnett
Project radio_button_checked
Assisting and Mapping
RP Assistant (CityRP)
Posts: 2,967
Threads: 177
Likes Given: 2838
Likes Recieved: 1507 in 913 posts
Joined: Aug 2015
Reputation: 46
#3
Aug 31, 2016, 02:24 PM
Nice, but I think photobucket would not hurt anyone. (photobucket.com)
[Image: sO5GyCt.png]
(This post was last modified: Aug 31, 2016, 02:24 PM by Project.)
The following 1 user Likes Project's post:
  • Burnett
Arch.B radio_button_checked
The OG
Membership
Posts: 360
Threads: 29
Likes Given: 274
Likes Recieved: 312 in 177 posts
Joined: Oct 2015
Reputation: 5
#4
Aug 31, 2016, 02:27 PM
Its for the best so meh good work!

Inactive asf
Burnett radio_button_checked
Security Officer, CityRP2 Core Developer
Developer
Posts: 3,225
Threads: 201
Likes Given: 1419
Likes Recieved: 3280 in 973 posts
Joined: Aug 2015
Reputation: 45
#5
Aug 31, 2016, 02:35 PM
Added:

*.photobucket.com
*.pinimg.com
*.dropboxusercontent.com
*.steamstatic.com
*.tinypic.com
*.puu.sh
If you have questions regarding Limelight Gaming's security, infrastructure or backend related topics,
feel free to contact me directly via Discord or PM.
Please note that confidential information cannot be disclosed.

Burnett
(This post was last modified: Aug 31, 2016, 02:42 PM by Burnett.)
Burnett radio_button_checked
Security Officer, CityRP2 Core Developer
Developer
Posts: 3,225
Threads: 201
Likes Given: 1419
Likes Recieved: 3280 in 973 posts
Joined: Aug 2015
Reputation: 45
#6
Aug 31, 2016, 02:37 PM
People might ask "Why whitelist instead of blacklist?"

Well. The problem with a blacklist is: Someone could use a free webspace service to upload an malicious script with an embedded ip-logger and mask it as an image. Then the person could use that image on forums. It would be much harder to collect bad sites than whitelisting good ones
If you have questions regarding Limelight Gaming's security, infrastructure or backend related topics,
feel free to contact me directly via Discord or PM.
Please note that confidential information cannot be disclosed.

Burnett
H4MZ4 radio_button_checked
NoooooooOOoot NooOOOOOooOoooOot
Membership
Posts: 262
Threads: 75
Likes Given: 41
Likes Recieved: 56 in 39 posts
Joined: Dec 2015
Reputation: 4
#7
Aug 31, 2016, 03:27 PM
What about prntscr.com I forgot what their short link is but it's another screenshotntool
----------------
Notable Stuff By Me
AutoServerCleaner - Garry's Mod
Various Photon Configs + Skins - Garry's Mod
Sad Mac For Safe Mode - iOS-Cydia

The following 1 user Likes H4MZ4's post:
  • splash addict
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#8
Aug 31, 2016, 03:28 PM
Could we have vgy.me? As that's my go to site for ShareX screenshots
[Image: bkZ74Ui.png]
Jompe radio_button_checked
Contributor
Contributor
Posts: 403
Threads: 33
Likes Given: 793
Likes Recieved: 254 in 151 posts
Joined: Aug 2015
Reputation: 7
#9
Aug 31, 2016, 03:31 PM
Requesting https://dl.dropboxusercontent.com

EDIT: Does not work, even with the link on the whitelist.
[Image: Vmkhnx5.png]
(This post was last modified: Aug 31, 2016, 10:31 PM by Jompe.)
L=I²=Am³ radio_button_checked
(∩ಠᗜಠ)⊃━☆゚.* - - Banter
Membership
Posts: 103
Threads: 18
Likes Given: 52
Likes Recieved: 21 in 22 posts
Joined: Aug 2015
Reputation: 1
#10
Aug 31, 2016, 04:04 PM
Who knew people living in basements could do so much damage..
                                                                                                               Did i help you in any way? +REP me. (Please i need to feed my family)
thefaketaco radio_button_checked
October's Very Own
Membership
Posts: 736
Threads: 46
Likes Given: 347
Likes Recieved: 380 in 325 posts
Joined: Mar 2016
Reputation: 12
#11
Aug 31, 2016, 04:13 PM
I'm not even gonna say anything bad against the guy, if he has my IP I don't think he would have a problem DDOS'ing me for the next year if I talk shit
[Image: 200.gif#5]
Burnett radio_button_checked
Security Officer, CityRP2 Core Developer
Developer
Posts: 3,225
Threads: 201
Likes Given: 1419
Likes Recieved: 3280 in 973 posts
Joined: Aug 2015
Reputation: 45
#12
Aug 31, 2016, 04:48 PM
Added

prntscr.com
prnt.sc
dl.dropboxusercontent.com
vgy.me
If you have questions regarding Limelight Gaming's security, infrastructure or backend related topics,
feel free to contact me directly via Discord or PM.
Please note that confidential information cannot be disclosed.

Burnett
Bambo radio_button_checked
Server Jedi
Super Administrator (CityRP)
Posts: 3,831
Threads: 387
Likes Given: 1649
Likes Recieved: 3506 in 1231 posts
Joined: Aug 2015
Reputation: 62
#13
Aug 31, 2016, 05:54 PM
Short-url's can be checked from https://www.checkshorturl.com/ incase someone with no malicious intent uses a short-url

Also, someone can mask the link, make it look like something and link it somewhere else like this www.google.com so do be careful to that. It was already said in the thread but there's no harm in repeating a safety measure
[Image: elwbIh5.gif]
(This post was last modified: Aug 31, 2016, 05:58 PM by Bambo. Edited 1 time in total.)
The following 1 user Likes Bambo's post:
  • Burnett
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#14
Aug 31, 2016, 05:59 PM
If you ever encounter a goo.gl link that you don't know what is for, add a + to the end to view the analytics that includes the original URL.
[Image: bkZ74Ui.png]
Arch.B radio_button_checked
The OG
Membership
Posts: 360
Threads: 29
Likes Given: 274
Likes Recieved: 312 in 177 posts
Joined: Oct 2015
Reputation: 5
#15
Aug 31, 2016, 06:05 PM
You might want to add limelightgaming.net...

Inactive asf




Users browsing this thread: