PDA

View Full Version : Zenfolio unauthorized image access by URL


Axton
17th of February 2008 (Sun), 17:21
Good reason to watermark-

I posted a similar topic but though I should start a new one about URL links to Zenfolio images (I'm sure there's simliar methods with Smugmug, etc.).

I really like Zenfolio and will upgrade when my trial is over (my Zenfolio trial, that is. I'm not actually ON trial!)

The "send link" feature bothered me a little, but only because I can't completely remove the option from my viewer pages. I just realized the url shows in IE address bar anyway.

Found it pretty easy to access all file sizes of other users where I can right click, save file as...

For example:
Here is the "send link" url a visitor sees:
http://wishboxphoto.zenfolio.com/p480614314/?photo=572795791 (http://wishboxphoto.zenfolio.com/p480614314/?photo=572795791)

Just needs to be changed to this (everytime, doesn't matter who's site it is):
http://wishboxphoto.zenfolio.com/img/v3/p572795791-5.jpg (http://wishboxphoto.zenfolio.com/img/v3/p572795791-5.jpg)

(the "-5.jpg" represents the largest file, -4, -3, -2, etc. will give you different file sizes)

I know there is always a way someone will find if they want to steal your images, but this looks like reason enough to WATERMARK any images you want to protect.

pmk
17th of February 2008 (Sun), 18:28
Very interesting ... and somewhat disturbing.

Send your comment/question to ZF customer service to see what they say.

support@zenfolio.com

pmk

bobbyz
17th of February 2008 (Sun), 20:13
OK. Here is the send link

http://bobbyzphotography.com/p887515781/?photo=571059564

Now if I type

http://bobbyzphotography.com/img/v3//p571059564-5.jpg

Nothing happens.

BTW - You can totally disable the send link button, isn't it.

bobbyz
17th of February 2008 (Sun), 20:19
OK, I get what you saying

http://bobbyzphotography.com/p887515781/?photo=647997736

If you type

http://bobbyzphotography.com/img/v3/p647997736-5.jpg

You get the large size but I have enabled viewing of large size files. Can you get the original size from this? I haven't tried.

_aravena
17th of February 2008 (Sun), 20:34
Yeah, the largest they can see is 566X850 so..idk. I do watermark the images I don't want copied. There should be a way to disable that link though.

Axton
17th of February 2008 (Sun), 21:24
OK, I get what you saying

http://bobbyzphotography.com/p887515781/?photo=647997736

If you type

http://bobbyzphotography.com/img/v3/p647997736-5.jpg

You get the large size but I have enabled viewing of large size files. Can you get the original size from this? I haven't tried.

Yes, that's it... I think if anyone is determined enough, they can get to your images. I'm not saying that Zenfolio has weak security, I'm sure I could do the same with Smugmug, or any other site that hosts photos.

The "send link" option doesn't really matter if it's available to viewers or not because the url to the photo shows up in the address bar anyway.

The solution is to have a conspicuous watermark over a significant portion of the image, and even then, someone could remove that if they were psycho about it! What sucks is having a big watermark over your image - YUCK!

bobbyz
18th of February 2008 (Mon), 02:06
One thing I noticed that even after disabling "view large files", the above link mentioned to my large file still worked.

I think it would be good if folks let Zenfolio about this.

alexaf
18th of February 2008 (Mon), 02:46
Keep in mind that anything that is displayed on the Web to the general public can be stolen. It doesn't matter how difficult the URLs are, all it's needed is to hit the Print Screen button. The only real protection is access control.

One thing I noticed that even after disabling "view large files", the above link mentioned to my large file still worked.

I think it would be good if folks let Zenfolio about this.

Bobby, it looks like large images are enabled for this gallery (in fact, they are enabled for your entire Birds group). Also, make sure you are logged out when testing, since as the owner you can see any image size, including the original.

BTW, the URL to the original is http://bobbyzphotography.com/img/v3/p647997736.jpg.

To contact Zenfolio, either drop a line to support@zenfolio.com or use this form: http://www.zenfolio.com/zf/contact.aspx.

-- AF

Axton
18th of February 2008 (Mon), 10:38
I've sent Zenfolio a detailed message regarding the send link feature as well as a suggestion to have the option to block access to images via URL just as they do for the main image. Will post their response when I get it....

bobbyz
18th of February 2008 (Mon), 14:08
Keep in mind that anything that is displayed on the Web to the general public can be stolen. It doesn't matter how difficult the URLs are, all it's needed is to hit the Print Screen button. The only real protection is access control.



Bobby, it looks like large images are enabled for this gallery (in fact, they are enabled for your entire Birds group). Also, make sure you are logged out when testing, since as the owner you can see any image size, including the original.

BTW, the URL to the original is http://bobbyzphotography.com/img/v3/p647997736.jpg.

To contact Zenfolio, either drop a line to support@zenfolio.com or use this form: http://www.zenfolio.com/zf/contact.aspx.

-- AF

Thanks AF. I think I will contact Zenfolio about this URL of the original image.

_aravena
18th of February 2008 (Mon), 14:10
Zenfolio did do something. Anyone notice the folder look around your galleries has disappeared?

bobbyz
18th of February 2008 (Mon), 14:11
For some reason I can't access the original of this one.

http://bobbyzphotography.com/img/v3/p280307223-4.jpg

So some other option which I have enabled for my bird gallery which is allowing to get to original image.

Axton
18th of February 2008 (Mon), 17:02
Here is Zenfolio's reply:

Hello Al,

Thank you for contacting us.

1. You can hide the Send Link button from the Visitor pages. This is an aesthetic preference to help you make pages look cleaner, this is not meant as security.

It is not possible to completely remove the Send Link menu from the custom right-click or image menus as this is the way for viewers to get links to the photo page and the gallery.

2. The fact that it is difficult for the viewers to get direct links to public images is just a deterrent from casual stealing, just like the right-click disabled menu is a deterrent, not real protection.

Any image displayed in a Web browser can be extracted by someone who really wants to. That's why the real protection is under the Access Control where you can disable downloading original files and very large images. If you do that, those items will be truly secure.

Whether or not to use watermarking on your displayed images is completely up to you. This is no different then deciding on whether your viewers should see watermarked images displayed on your pages, because any of them can be taken with a PrtScn command.

Again, the real protection lays in the Access Control settings which make items truly secure.

Hope this makes sense.

Regards,
Zenfolio Customer Support

That's just how it is, I mean if someone wants to get to the images, no matter they are, there's always a way... I'm still going with Zenfolio for my online host!

azneric3
20th of February 2008 (Wed), 01:35
good find!