Original viewed when not allowed

W.W. WebsterW.W. Webster Registered Users Posts: 3,204 Major grins
edited February 24, 2006 in SmugMug Support
I have been surprised to find that a visitor to my site has apparently been able to view a photo on my site in 'original' size (but, hopefully, not copy it) when the relevant gallery customisation parameter that would enable this ('can people view your original, full size photos?') is set to 'no'.

An extract of the StatCounter log which revealed this problem follows. When I click on the reported URL, it brings up the image in 'large ' size, but enables me select 'original' which then appears to become the new default. Can anyone explain what is going on here?

57444229-L.jpg

Comments

  • cyoungcyoung Registered Users Posts: 81 Big grins
    edited February 23, 2006
    Hi Ross, I looked at your gallery and went thru Large to access the original, but ar your original resolution 800X566? The original size seems to be the same resolution as a large photo, but I'm no expert, just curious myselfne_nau.gif. I'll let the smughouse pros chime in...
    I have been surprised to find that a visitor to my site has apparently been able to view a photo on my site in 'original' size (but, hopefully, not copy it) when the relevant gallery customisation parameter that would enable this ('can people view your original, full size photos?') is set to 'no'.

    An extract of the StatCounter log which revealed this problem follows. When I click on the reported URL, it brings up the image in 'large ' size, but enables me select 'original' which then appears to become the new default. Can anyone explain what is going on here?

    57444229-L.jpg
    -Carey

    Canon EOS Rebel XT, EF-S 18-55, EF 50 1.8 II, Tamron AF 19-35 3.5-4.5, EF 24-70 f/2.8L, EF 70-200 f/4L, Speedlite 580EX, Manfrotto Digi Mini 718B.
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 23, 2006
    cyoung wrote:
    Hi Ross, I looked at your gallery and went thru Large to access the original, but ar your original resolution 800X566? The original size seems to be the same resolution as a large photo, but I'm no expert, just curious myselfne_nau.gif. I'll let the smughouse pros chime in...

    i'm pretty sure this is the designed behavior. instead of showing a 404 or something like that, it shows the maximum allowed size, be that large or medium (if larges are disabled).
    Pedal faster
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 23, 2006
    I have been surprised to find that a visitor to my site has apparently been able to view a photo on my site in 'original' size (but, hopefully, not copy it) when the relevant gallery customisation parameter that would enable this ('can people view your original, full size photos?') is set to 'no'.
    Under normal circumstances you don't get the original by adding /Original to the url. So don't worry - the person just got your large picture even though he somehow accessed the original-link.

    But through this I acutally found a way of accessing the Originals by mistake! I'm gonna send this straight to smugmug and won't describe the bug here further.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • RetaggerRetagger Registered Users Posts: 46 Big grins
    edited February 23, 2006
    Security Concern
    Under normal circumstances you don't get the original by adding /Original to the url. So don't worry - the person just got your large picture even though he somehow accessed the original-link.

    But through this I acutally found a way of accessing the Originals by mistake! I'm gonna send this straight to smugmug and won't describe the bug here further.

    Sebastian

    Hello Sebastian,

    Please let us know if this problem has been corrected by Smugmug. If you found a "Backdoor" to access the original photos, that is a SERIOUS problem that must be corrected ASAP.

    Thanks,

    David....
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 23, 2006
    Retagger wrote:
    Please let us know if this problem has been corrected by Smugmug. If you found a "Backdoor" to access the original photos, that is a SERIOUS problem that must be corrected ASAP.
    David,
    word about it is out to smugmug. I'm sure they'll take care of it ASAP! thumb.gif

    Stay tuned,
    Sebastian
    Sebastian
    SmugMug Support Hero
  • dogwooddogwood Registered Users Posts: 2,572 Major grins
    edited February 23, 2006
    yeah... i've had this happen too
    I had a make-up artist tell me she could open up and download my originals, even though everything was set so that wouldn't happen. I don't know how she did it though. Now, I post my galleries small (450 pixels tall) with a copyright notice on them. Then in the description, I put a link that says something like "to order prints, click here".

    And that goes to a gallery all stamped with the "proof" and only enabled to view large (not original). As of yet, the photos people are stealing are the small copyright ones (I see them on myspace.com profiles). But they avoid the "proof" ones. Anyway, I try to put the copyright notice in a place that makes it tougher than a quick crop to remove.

    It's a brutal on-line world for us photographers who actually want to sell anything!

    Portland, Oregon Photographer Pete Springer
    website blog instagram facebook g+

  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 23, 2006
    I have Andy Williams originals for sale. Buy one get 1 free!
    Pedal faster
  • W.W. WebsterW.W. Webster Registered Users Posts: 3,204 Major grins
    edited February 23, 2006
    Thanks for taking the trouble to provide your feedback and comments, everyone.
  • BenBen Vanilla Admin Posts: 513 SmugMug Employee
    edited February 23, 2006
    yeah... to reiterate what others have said, the /Original url will only show the largest possible size. No reason to alert people they aren't getting the actual Original... that just encourages them to try and be devious. :)

    So you can get traffic on the /Original, but it won't actually give them the original. We have seen people claiming to have downloaded Original images too, and whenever we ask to see an example, it is always a large or medium. They just don't realize that they don't have the "high res original" because they have a pretty big sized picture (to them). To a non-photographer, those big Larges (and even Mediums to people on small monitors) look very high res and "original".
    Smug since 2003
  • RetaggerRetagger Registered Users Posts: 46 Big grins
    edited February 23, 2006
    If there is a back door open on Smugmug to obtain the original files, as Sabastain has said, this must be a top priority for them. Let us know something.

    David...
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited February 23, 2006
    Retagger wrote:
    If there is a back door open on Smugmug to obtain the original files, as Sabastain has said, this must be a top priority for them. Let us know something.

    David...
    Retagger,

    There are no back doors. Please look at JTs post above and these two links here:

    http://www.moonriverphotography.com/gallery/1022944/1/47425794/Large
    http://www.moonriverphotography.com/gallery/1022944/1/47425794/Original

    Same photo. Same size. If you have Originals blocked, and someone goes to a /Original url, they will be served up the /Large size. If you have Larges blocked, they'll be served up the /Medium size.

    I hope this clears up the confusion for you. If you have any questions, holler back.

    All teh best,
  • RetaggerRetagger Registered Users Posts: 46 Big grins
    edited February 23, 2006
    Hello Andy,

    I understand what you have written above. I am referring to the comments by Sabastian claiming that while investigating whether the original and the large files were infact the same, he claims that he found another way to obtain the original file. Is there any merit to his claim?

    David...
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited February 23, 2006
    Retagger wrote:
    Is there any merit to his claim?

    David...

    Nope. If you have Originals blocked in your galleries, visitors can't get to them.
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 24, 2006
    Retagger wrote:
    If there is a back door open on Smugmug to obtain the original files, as Sabastain has said, this must be a top priority for them. Let us know something.
    David,
    I just got out of bed and checked on this. The issue I reported before is fixed. No need to worry anymore.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 24, 2006
    bigwebguy wrote:
    I have Andy Williams originals for sale. Buy one get 1 free!
    I don't see anything funny in this. rolleyes1.gif

    Sebastian
    Sebastian
    SmugMug Support Hero
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 24, 2006
    I don't see anything funny in this. rolleyes1.gif

    Sebastian

    ne_nau.gif
    Pedal faster
  • devbobodevbobo Registered Users, Retired Mod Posts: 4,339 SmugMug Employee
    edited February 24, 2006
    I don't see anything funny in this. rolleyes1.gif

    Sebastian

    Sebastian,

    yes it is a serious issue that was well picked up thumb.gif

    but it's the kinda thing that you have gotta see the funny side of, that was Lee's intention.

    Cheers,

    David
    David Parry
    SmugMug API Developer
    My Photos
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 24, 2006
    I don't see anything funny in this. rolleyes1.gif

    Sebastian
    57502266-L.gif
    Pedal faster
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 24, 2006
    devbobo wrote:
    but it's the kinda thing that you have gotta see the funny side of, that was Lee's intention.
    Yeah, but I'm not exactly sure if he jokes or not. He probably is, but it's just he asked me if I wanted a second opinion on the bug and even so I was 100% sure I sent it to him. What I got back was 'holy shit' and 'I'm gonna download me some andy williams originals'. Even though it was probably meant in a funny way, I felt bad about sending it to him and couldn't laugh at all about his joke. Probably because a smiley was missing.

    So now this is off my chest. I don't mind posting this in public as he somewhat repeated his joke over here.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 24, 2006
    Yeah, but I'm not exactly sure if he jokes or not. He probably is, but it's just he asked me if I wanted a second opinion on the bug and even so I was 100% sure I sent it to him. What I got back was 'holy shit' and 'I'm gonna download me some andy williams originals'. Even though it was probably meant in a funny way, I felt bad about sending it to him and couldn't laugh at all about his joke. Probably because a smiley was missing.

    So now this is off my chest. I don't mind posting this in public as he somewhat repeated his joke over here.

    Sebastian
    I also said "well done"

    Also recognize that I'm a mod and it should be understood that i'm not going to exploit any knowledge that i may gain as being one.

    It was meant more as a joke for Andy so it was a mistake on my part to even say it.
    Pedal faster
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 24, 2006
    bigwebguy wrote:
    I also said "well done"

    Also recognize that I'm a mod and it should be understood that i'm not going to exploit any knowledge that i may gain as being one.

    It was meant more as a joke for Andy so it was a mistake on my part to even say it.
    Yeah, you did and I know you're a mod, that's why I send it to you in the first place. It's nothing personal against you, it's just that I'm a bit odd in these kind of situations and tend to misinterprete stuff easily. Also it adds up that I've trouble detecting sarcasm and irony - thus reading too much stuff literary, especially when it's in written form.

    Actually I'm glad you posted it here too - help to clear everything up for me.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • DodgeV83DodgeV83 Registered Users Posts: 379 Major grins
    edited February 24, 2006
    So he really WAS able to get originals??? What the hell man!?

    Maybe he shouldn't post how it was done, incase a similar bug exists...but still! WHAT THE HELL MAN!?

    It was probably lightbox related...
  • bwgbwg Registered Users, Retired Mod Posts: 2,119 SmugMug Employee
    edited February 24, 2006
    DodgeV83 wrote:
    So he really WAS able to get originals??? What the hell man!?

    Maybe he shouldn't post how it was done, incase a similar bug exists...but still! WHAT THE HELL MAN!?

    It was probably lightbox related...

    the bug wont be posted, at least by any of us here.

    and it wasnt lightbox related, so put your torch out.
    Pedal faster
  • devbobodevbobo Registered Users, Retired Mod Posts: 4,339 SmugMug Employee
    edited February 24, 2006
    DodgeV83 wrote:
    It was probably lightbox related...

    lol3.giflol3
    David Parry
    SmugMug API Developer
    My Photos
  • devbobodevbobo Registered Users, Retired Mod Posts: 4,339 SmugMug Employee
    edited February 24, 2006
    Yeah, but I'm not exactly sure if he jokes or not. He probably is, but it's just he asked me if I wanted a second opinion on the bug and even so I was 100% sure I sent it to him. What I got back was 'holy shit' and 'I'm gonna download me some andy williams originals'. Even though it was probably meant in a funny way, I felt bad about sending it to him and couldn't laugh at all about his joke. Probably because a smiley was missing.

    So now this is off my chest. I don't mind posting this in public as he somewhat repeated his joke over here.

    Sebastian
    Hey Sebastian,

    Unfortunately, it's sometime difficult to read the undertones of a post (unless they use smilies mwink.gif).

    But I can, somewhat relucantly, confirm that BWG does infact have a wicked sense of humour lol3.giflol3

    Dave
    David Parry
    SmugMug API Developer
    My Photos
  • DodgeV83DodgeV83 Registered Users Posts: 379 Major grins
    edited February 24, 2006
    devbobo wrote:
    lol3.giflol3

    hehe, actaully I was hoping it WAS lightbox related! At least that way our Originals would only recently have been vulnerable.

    Is there anyway I can see if anyone was using that bug on my site?
  • rainforest1155rainforest1155 Registered Users Posts: 4,566 Major grins
    edited February 24, 2006
    DodgeV83 wrote:
    hehe, actaully I was hoping it WAS lightbox related! At least that way our Originals would only recently have been vulnerable.

    Is there anyway I can see if anyone was using that bug on my site?
    See the release notes. I stumbeled on the bug by accident and it is fixed now.
    What Webster (thread starter) noticed was someone clicking on an Original link that just lead to the Large picture again, because Originals were disabled in the gallery.

    Sebastian
    Sebastian
    SmugMug Support Hero
  • DodgeV83DodgeV83 Registered Users Posts: 379 Major grins
    edited February 24, 2006
    See the release notes. I stumbeled on the bug by accident and it is fixed now.
    What Webster (thread starter) noticed was someone clicking on an Original link that just lead to the Large picture again, because Originals were disabled in the gallery.

    Sebastian

    You guys should hire Sebastian to find more bugs ;)

    Seriously though, I really hope nobody has used this! If Sebastian could stumble upon it by mistake, I'm sure someone looking for it could've found it! Lets hope their statement is accurate "As far as we can tell, no-one ever used it"
  • RetaggerRetagger Registered Users Posts: 46 Big grins
    edited February 24, 2006
    David,
    I just got out of bed and checked on this. The issue I reported before is fixed. No need to worry anymore.

    Sebastian
    Sabastian, you are the man! Thank you. clap.gif

    I was originally told that there was no backdoor and as long as the "Originals" were off, that I was safe. But this proved them wrong. If Microsoft can get hacked, so can this site. I am glad that the techs fixed the problem so quickly though.

    David...
Sign In or Register to comment.