Bitcoin Forum
April 27, 2024, 02:45:21 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Allow SVG on Signatures :)  (Read 223 times)
Bitcoin.PN (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 28
Merit: 24

Bitcoin.PN - Bitcoin Play Network Coming Soon!


View Profile WWW
April 18, 2022, 08:21:47 PM
 #1

Hey guys, I know images are not allowed in signatures, but what about SVG?

It's vectors and it doesn't need to load images from external sources.

Just a thought

Bitcoin.PN - Bitcoin Play Network Coming Soon!
1714185921
Hero Member
*
Offline Offline

Posts: 1714185921

View Profile Personal Message (Offline)

Ignore
1714185921
Reply with quote  #2

1714185921
Report to moderator
1714185921
Hero Member
*
Offline Offline

Posts: 1714185921

View Profile Personal Message (Offline)

Ignore
1714185921
Reply with quote  #2

1714185921
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2016
Merit: 1781


฿itcoin for all, All for ฿itcoin.


View Profile
April 18, 2022, 09:57:04 PM
Merited by Pmalek (1)
 #2

I doubt if they will allow the on signatures. Initially they were not even allowed on forum ads whose slots go through auctions

Images are not allowed no matter how they are created (CSS, SVG, or data URI). Occasionally I will make an exception for small logos and such, but you must get pre-approval from me first.

Later on, according to this, they are allowed but with some restrictions

Quote
You can include images, but they must be base64-encoded data: URIs. No <svg> tags; SVG images are allowed, but they must be base64-encoded in data

There must be a reason.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 2856
Merit: 3071


https://bit.ly/387FXHi lightning theory


View Profile
April 18, 2022, 10:33:47 PM
Merited by DarkStar_ (5), ABCbits (3), BitMaxz (1), Pmalek (1)
 #3

Quote
You can include images, but they must be base64-encoded data: URIs. No <svg> tags; SVG images are allowed, but they must be base64-encoded in data

There must be a reason.

It's possible to hide malicious code in an svg (it's likely scannable and easy to detect but there's probably not much point seen in taking the risk).

A simple way svg can be used for hacking would be by adding a closing svg tag inside the image you've uploaded and then adding your onw html/javascript/php straight after it (you can add a closing svg at the end of that too to get it to be less likely to be detected - I'm posting this as an example because I don't expect it to work ANYWHERE).
dkbit98
Legendary
*
Offline Offline

Activity: 2212
Merit: 7071


Cashback 15%


View Profile WWW
April 19, 2022, 10:07:42 AM
 #4

Hey guys, I know images are not allowed in signatures, but what about SVG?
Quality of signatures would for sure be much better with vector graphics, but I am not sure if I ever saw a forum that has svg signatures, and I am not sure we even need that.
I think that theymos is trying to reduce all the risks and I don't expect to see any changes with signatures, at least not with current forum software.
You an get very good signatures for your business even now, if you pick a good designer.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
aysg76
Legendary
*
Offline Offline

Activity: 1960
Merit: 2124



View Profile
April 19, 2022, 10:46:22 AM
 #5


It's possible to hide malicious code in an svg (it's likely scannable and easy to detect but there's probably not much point seen in taking the risk).

A simple way svg can be used for hacking would be by adding a closing svg tag inside the image you've uploaded and then adding your onw html/javascript/php straight after it (you can add a closing svg at the end of that too to get it to be less likely to be detected - I'm posting this as an example because I don't expect it to work ANYWHERE).
Yes and hackers are always trying to find out new ways to scam you so the forum security needs to be updated with it and trying new things in signature space with svg can result in those malicious codes you are talking about.

One google search landed me on stackoverflow results where user received malicious code embedded in JS redirecting him to phising YouTube page that could harm his system .

Quality of signatures would for sure be much better with vector graphics, but I am not sure if I ever saw a forum that has svg signatures, and I am not sure we even need that.
I think that theymos is trying to reduce all the risks and I don't expect to see any changes with signatures, at least not with current forum software.
You an get very good signatures for your business even now, if you pick a good designer.
The quality can be improved with vector signatures but if the security is compromised so what's the need to do it? Moreover at this time the signatures are looking fine even in the pixelated format and forum is doing quite well in them.Yes i also think there is any vector signature on the forum or any particular thread about it because i have searched it and found nothing related to this.So at this time we are absolutely best without superior quality also with security.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
Bitcoin.PN (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 28
Merit: 24

Bitcoin.PN - Bitcoin Play Network Coming Soon!


View Profile WWW
April 19, 2022, 04:35:32 PM
 #6

So sick. I didn't know one could hide code in an svg file. Literally just checked my site's SVG files and all seem healthy Smiley

Bitcoin.PN - Bitcoin Play Network Coming Soon!
UserU
Hero Member
*****
Offline Offline

Activity: 2016
Merit: 531


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
April 20, 2022, 05:07:57 PM
 #7

So sick. I didn't know one could hide code in an svg file. Literally just checked my site's SVG files and all seem healthy Smiley

Those common image files could be code-injected.

Really unimaginable huh when people could find almost anything to have it their way Smiley

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█
▄▄▄▀▀▀▀▀▀▀▄▄▄
▄▄▀▀▄ ▄ ▀ ▀ ▀ ▄ ▄▀▀▄▄
▄▀▄ ▀               ▀ ▄▀▄
█ ▄                     ▄ █
█ ▄  █████  ▄███▄  ▄███▄  ▄ █
█ ▄   ██▄▄   ██ ██  ██ ██   ▄ █
█ ▄   ▀▀▀██  ██ ██  ██ ██   ▄ █
█ ▄   ▄▄ ██  ██ ██  ██ ██   ▄ █
█ ▄  ▀███▀  ▀███▀  ▀███▀  ▄ █
█ ▄                     ▄ █
▀▄ ▀ ▄             ▄ ▀ ▄▀
▀▀▄▄ ▀ ▄ ▄ ▄ ▄ ▀ ▄▄▀▀
▀▀▀▄▄▄▄▄▄▄▀▀▀

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
Bitcoin.PN (OP)
Copper Member
Newbie
*
Offline Offline

Activity: 28
Merit: 24

Bitcoin.PN - Bitcoin Play Network Coming Soon!


View Profile WWW
April 20, 2022, 09:00:41 PM
 #8

So sick. I didn't know one could hide code in an svg file. Literally just checked my site's SVG files and all seem healthy Smiley

Those common image files could be code-injected.

Really unimaginable huh when people could find almost anything to have it their way Smiley

Yeah, I really couldn't think one could inject code in a xvg file. Very interesting stuff.

Bitcoin.PN - Bitcoin Play Network Coming Soon!
FFrankie
Hero Member
*****
Offline Offline

Activity: 2254
Merit: 960

100% Deposit Match UP TO €5000!


View Profile
April 21, 2022, 11:17:13 PM
 #9

Quote
You can include images, but they must be base64-encoded data: URIs. No <svg> tags; SVG images are allowed, but they must be base64-encoded in data

There must be a reason.

It's possible to hide malicious code in an svg (it's likely scannable and easy to detect but there's probably not much point seen in taking the risk).

A simple way svg can be used for hacking would be by adding a closing svg tag inside the image you've uploaded and then adding your onw html/javascript/php straight after it (you can add a closing svg at the end of that too to get it to be less likely to be detected - I'm posting this as an example because I don't expect it to work ANYWHERE).


How do we bring this up but do not bring up the guy who included the 1 pixel by 1 pixel tracking image in his url
uchegod-21
Hero Member
*****
Offline Offline

Activity: 924
Merit: 593


BTC, a coin of today and tomorrow.


View Profile
April 21, 2022, 11:35:09 PM
 #10

Hey guys, I know images are not allowed in signatures, but what about SVG?
Quality of signatures would for sure be much better with vector graphics, but I am not sure if I ever saw a forum that has svg signatures, and I am not sure we even need that.
I think that theymos is trying to reduce all the risks and I don't expect to see any changes with signatures, at least not with current forum software.
You an get very good signatures for your business even now, if you pick a good designer.

I have taught of why signature designers doesn't use SVG to achieve fine and scalable designs. But I didn't attribute it to risk of vulnerabilities or maliciousness. I just concluded that signature space is not that much, only the vector codes will occupy the majority space of the signature space. I couldn't remember that Theymos can increase the signature space, then the whole system can be loading slowly.
I believe Theymos doesn't want to include anything that will not benefit the forum, it's not worth risking.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!