protection
French 
CrawlTrack, webmaster dashboard.
Web analytic, SEO and protection

CrawlProtect, your website safety.
Reinforced protection

Two php/MySQL scripts, free and easy to install
The tools you need to manage and keep control of your site.





diable

CrawlTrack and CrawlProtect support forum

You are not logged in.


#1 27-03-2011 22:21:47

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

CrawlProtect blocking embedded media

Greetings dev.s,

Let me first thank you for all your hard work in helping us protect our sites.

I run a PHP-Fusion site for a local shooting club as a hub for social interaction and information. As I have used PHP-Fusion before and gotten hacked I wanted to build in as much security this time around as possible and found your package very useful. There's just one problem:

It's blocking access to YouTube videos and such in my forum. I was wondering if this didn't have to do with the built-in XSS protection that's built into CrawlProtect so I tested it. I went into the admin panel of CrawlProtect and had it not cover my IP address in its protection scheme. I then went back to my forum and checked the post with the YouTube video embedded in it and suddenly it was there again. I then went back to the admin panel, had it cover all IP addresses again and went back to the forum to find it gone, again.

Since this indicates that CrawlProtect is blocking cross-site embedding of multimedia I was wondering if there was a way to unblock certain domains, such as YouTube. Is there a work-around that I can implement? Would this be a good thing to implement in the next iteration of your package?

Any help would be appreciated,

LJ

Offline

 

#2 01-04-2011 15:11:45

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

Re: CrawlProtect blocking embedded media

Could really use some help with this, folks. Anyone?

cool LJ

Offline

 

#3 01-04-2011 19:32:17

Jidébé
Administrateur
Registered: 30-10-2005
Posts: 2923

Re: CrawlProtect blocking embedded media

Hi,

There is no easy option yet to unblock certain domain. It will certainly be part of a future release.

What did you get in your CrawlProtect log?

Jean-Denis


CrawlTrack & CrawlProtect developer

Offline

 

#4 02-04-2011 07:28:12

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

Re: CrawlProtect blocking embedded media

Hi Jean-Denis,

Thank you so much for your reply to my question. In answer to your own question: the log, so far, is empty.

Under "List of IP blocked by the htaccess" the box is empty.

Under "List of referers blocked by the htaccess" the box is empty.

But, since the request is coming FROM my website TO YouTube, I have to wonder if there would be any log at all since the two fields I mentioned above are for INCOMING traffic, not out-going. Or am I misunderstanding this?

Any further help would be much appreciated.

LJ

Offline

 

#5 11-04-2011 18:04:16

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

Re: CrawlProtect blocking embedded media

Hell again, Jean-Denis,

Still waiting on an answer to my last post. Since my crawlprotect log was/is empty, what does this tell us? What does this indicate?

I apologize. I really don't wish to badger you. I am new to this type of security so I am sure I seem rather naive. I am also aware that you must be a very busy man. But, is there no such thing as an "ALLOW" statement of some kind that I could put in the .htaccess file for youtube and/or other sites to tunnel (for lack of a better term) through at my discretion? There must be some workaround.

I can access and edit the .htaccess file with no problem. I just need to know what to put in there to make things work. Any ideas?

Thanks in advance,

LJ

Last edited by Lord_Jereth (11-04-2011 18:04:34)

Offline

 

#6 11-04-2011 20:06:47

Jidébé
Administrateur
Registered: 30-10-2005
Posts: 2923

Re: CrawlProtect blocking embedded media

Hi,

Can you give me some example of url where you have the problem.

Jean-Denis


CrawlTrack & CrawlProtect developer

Offline

 

#7 11-04-2011 21:04:41

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

Re: CrawlProtect blocking embedded media

Hello again, Jean-Denis,

Thank you so much for your speedy reply. In answer to your question, honestly, it might just be easier to show you.

http://www.swamproadsportsmansclub.com/forum/viewthread.php?thread_id=2

This is a forum thread on my website. In that post you will see a link to the youtube video in question. What you don't see is that above that link is supposed to be the same video embedded on the page. When I have CrawlProtect set to not block my own IP address, that video shows up just fine in the thread. When I turn it back off, it disappears again. Either way, no one else can see that video unless they click the link and go to youtube, thereby leaving my site, to view it.

I am assuming that this is due to the XSS protection in my .htaccess file. If this is true, then I would assume all such cross site media embedding will be affected. This is merely an assumption as I have not yet tested embedding media from other sites. Youtube will most likely be the main video site that is used to embed media on my forum so that is the one I am most concerned about at the moment.

Thank you again and I hope to hear from you soon,

LJ

Last edited by Lord_Jereth (11-04-2011 21:05:59)

Offline

 

#8 11-04-2011 21:30:25

Jidébé
Administrateur
Registered: 30-10-2005
Posts: 2923

Re: CrawlProtect blocking embedded media

Hi,

I will send you by email a new createhtaccess.php file.
Replace the existing one (content folder) with that one and then recreate your htaccess.

Jean-Denis


CrawlTrack & CrawlProtect developer

Offline

 

#9 11-04-2011 21:51:33

Lord_Jereth
Nouveau membre
Registered: 27-03-2011
Posts: 6

Re: CrawlProtect blocking embedded media

Jean-Denis,

You, Sir, are a true professional. It is wonderful to see someone who takes their programming and customer relations so seriously and in such a timely manner.

The change works perfectly. Videos embedded from youtube, and I assume all video sites due to the changes I noticed in the newly rendered .htaccess file, work beautifully.

Thank you for your speedy replies and quick action in this matter. It is appreciated more than you know.

LJ

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2008 PunBB