Photos originals available to anyone with the link

icdvalicdval Registered Users Posts: 6 Beginner grinner
edited September 27, 2015 in Bug Reporting
Testing security of my photos I found that I'm able to see photo original jpgs that are inside a private gallery, with medium sizes as maximum view size, and with sharing option is off. This when logged out.

For my thinking the galleries are fully accesible, I know that is hard to get the link, but is not impossible.

Comments

  • RichardRichard Administrators, Vanilla Admin Posts: 19,967 moderator
    edited September 27, 2015
    Are you sure you aren't seeing something that's cached in your browser? Try it with a different browser and see what happens.
  • icdvalicdval Registered Users Posts: 6 Beginner grinner
    edited September 27, 2015
    I was hopping the same, but not, I tried in different browers, differents devices, in private tabs, used ctrl-f5 to refresh... the image always load, is not the cache...
  • RichardRichard Administrators, Vanilla Admin Posts: 19,967 moderator
    edited September 27, 2015
    That's troubling. I suggest you contact the SmugMug help desk (help@SmugMug.com) with the details.
  • icdvalicdval Registered Users Posts: 6 Beginner grinner
    edited September 27, 2015
    If you have any size URL of a photo, is very easy to figure the URL for the original photo...
    Can anyone try it with your photos?
  • RichardRichard Administrators, Vanilla Admin Posts: 19,967 moderator
    edited September 27, 2015
    I'm fairly sure that doesn't work beyond the maximum size permitted in the gallery. I do remember a scare I had many years ago when I saw stats that showed originals being accessed. It turned out that the stats were showing the number of requests, not the actual images served. So someone could edit the URL to try to get the original, but the actual image served was the user-specified maximum. Don't know whether the stats have been changed since then, but I would think so.
  • icdvalicdval Registered Users Posts: 6 Beginner grinner
    edited September 27, 2015
    I have reported but they said that I'm doing something wrong...

    I have to do more testing, some image load only the X3 size
  • icdvalicdval Registered Users Posts: 6 Beginner grinner
    edited September 27, 2015
    maybe is my ISP cache.... I'm going to close this until, just to do more testing and not alarm more people... as I was... sorry
Sign In or Register to comment.