Previous Thread
Next Thread
Print Thread
Hop To
Joined: Jun 2008
Posts: 154
N
Naz
Offline
member
member
N Offline
Joined: Jun 2008
Posts: 154
Hi - I think I may have posted this earlier in the wrong section (Poll - Your top feature you want for 7.5) and as far as I am aware presently its not possible to load a web page into your post, but is this something which is possible, if so I would dearly like to see this feature to be part of UBB.threads.

P.S: I am not sure if there would be any performance issues that would be of great concern, even so I think a restricted implementation by only allowing the admin or the person who starts the thread may be an idea.

Any thoughts ......most welcome smile

Last edited by Naz; 10/25/2008 6:56 AM.

Naz.
[The world is big enough for everyone - so be HAPPY smile ]
Joined: Dec 2006
Posts: 1,235
veteran
veteran
Joined: Dec 2006
Posts: 1,235
If you have HTML enabled could you use embed or iframe tags?

Joined: Aug 2006
Posts: 1,360
Likes: 2
Y
Veteran
Veteran
Y Offline
Joined: Aug 2006
Posts: 1,360
Likes: 2
Or you could make custom ubb tags for it.


[Linked Image from siemons.org]
Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
If you would make custom tags and allow users to load a web page within a post you might as well just turn on HTML in posting for everyone. If someone wanted to execute some bad code an they were not allowed to do it as HTML is off but you are able to pull in a web page using an IFRAME tag then they would do it that way.

Years ago this was used to execute a javascript code in a community and used to grab the Host's user names and passcodes, it worked very well and caused big problems in that community as the grabbed data was sent off to a perl program running in a different location on the internet.

Joined: Jun 2008
Posts: 154
N
Naz
Offline
member
member
N Offline
Joined: Jun 2008
Posts: 154

Originally Posted by Thelockman
If you would make custom tags and allow users to load a web page within a post you might as well just turn on HTML in posting for everyone. If someone wanted to execute some bad code an they were not allowed to do it as HTML is off but you are able to pull in a web page using an IFRAME tag then they would do it that way.

Years ago this was used to execute a javascript code in a community and used to grab the Host's user names and passcodes, it worked very well and caused big problems in that community as the grabbed data was sent off to a perl program running in a different location on the internet.

I'm assuming when you say by grabbing the host's user name and pass codes - thats for the web server where the web site lives, but why not just implement a browser functionality. So just as a browser loads a page why would there be any problems ( do you mean performance issues ), I guess I'm not clear on the latter part of your statement. But don't we load pages without difficulty in our browser window - and isn't it possible to replicate that. confused




Last edited by Naz; 10/25/2008 5:58 PM.

Naz.
[The world is big enough for everyone - so be HAPPY smile ]
Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
No, I think you have missed the point of the post.

If I wrote a script in javascript and placed it in a web post and the user loaded the web post in his or her browser it would run in that post like it was taken from that site.

Now you can not read cookies across web domains but if added to a post on that web domain you can use a hidden javascript to read the viewers user name and pass code from that domain name. Then if that script sent that information without you knowing it to another place that just logged all that information for future retrieval by someone that implanted the script they can use your log in information to be you.

Allowing users to load web pages into a forum like this is a disaster waiting to happen. Also the use of HTML in a web forum is also a disaster waiting to happen for many more reasons.

Not everyone out there is honest and or trustworthy. Give them a change to do harm to your site or board and they will take it if they are that type of person. I guarantee it. It is your site, do what you want. But if you do and someone is evil enough to take advantage of you and your allowing HTML or web pages in posts and your site is hijacked please don't come back and give the expression you were "hacked".

Joined: Jun 2008
Posts: 154
N
Naz
Offline
member
member
N Offline
Joined: Jun 2008
Posts: 154
^ thanks, point taken smile

though it would be ok for an ADMIN or a trusted set of people belonging to a 'Group' could be given permissions - would work if I understand you correctly and am not mistaken.

Last edited by Naz; 10/26/2008 7:44 AM.

Naz.
[The world is big enough for everyone - so be HAPPY smile ]
Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
Right, Your understanding me correctly.


Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
PHP 8 bug in membermanage.tmpl
by phoenix011235 - 09/08/2026 7:47 PM
Are any of these legitmate?
by Baldeagle - 09/06/2026 1:37 PM
8.0.1 Patch Changelog Discussion
by isaac - 11/26/2025 1:34 PM
Upgraded to ver8 - now can't login
by phoenix011235 - 10/24/2024 8:50 AM
Who's Online Now
2 members (SteveS, vscope), 455 guests, and 117 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Ride safe!
Ride safe!
by Morgan, December 7
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Powered by UBB.threads™ PHP Forum Software 8.1.0
(Snapshot build 20260527)