Simple Machines Community Forum

Archived Boards and Threads... => Archived Boards => SMF Feedback and Discussion => Aiheen aloitti: chadon - maaliskuu 14, 2008, 04:36:57 IP

Otsikko: Hot linking = danger?
Kirjoitti: chadon - maaliskuu 14, 2008, 04:36:57 IP
Over the years, hundreds of web pages are hot linking to images hosted on my server. It may use a lot of bandwidth but it also brings traffic from image search engines so I don't mind it. I recently converted my website to SMF and as this software is not displaying images with their real path I was wondering if it would be a problem if they are hot linked. Every time an image is loaded it has to go via a php file that may use a few MySQL queries. I don't want to have my server shut down from too much CPU usage as it is sometimes at it's maximum. Should I be concerned? If so, is there a way to display the images uploaded in the forum with the real path like: <img src="site.com/smf/uploads/photo.jpg">?
I know I can set permissions to what group can see the photos or prevent hot linking with .htaccess but I don't want to do it if there is a way to save CPU usage.
Thanks.
Otsikko: Re: Hot linking = danger?
Kirjoitti: H - maaliskuu 14, 2008, 05:26:15 IP
What I do is restrict hotlinking it the referrer is either not by own site or a blank referrer. This way my visitor get images and so do search engines that have blank referrers. This can easily be placed in .htaccess
Otsikko: Re: Hot linking = danger?
Kirjoitti: chadon - maaliskuu 14, 2008, 05:59:24 IP
 Yes but from what I saw, some users may not be able to view the images.
LainaaBut the facts remain that you shouldn't block on blank referrer alone unless you can afford to lose a lot of users who are behind corporate or ISP caching proxies, and that serious protection against bandwidth leeching requires a script/cookies solution.
from: Webmasterworld (http://www.webmasterworld.com/forum92/2934.htm)
I don't really want to block anyone but save the CPU usage because of the way SMF hosts the images.
Otsikko: Re: Hot linking = danger?
Kirjoitti: metallica48423 - maaliskuu 14, 2008, 06:01:10 IP
are you speaking more as to attachments?

Otsikko: Re: Hot linking = danger?
Kirjoitti: chadon - maaliskuu 14, 2008, 06:04:14 IP
Yes, I am talking about the attachments. My old forum was displaying them with their real path and that's what I would like to do.
Otsikko: Re: Hot linking = danger?
Kirjoitti: H - maaliskuu 14, 2008, 07:01:58 IP
Lainaus käyttäjältä: chadon - maaliskuu 14, 2008, 05:59:24 IP
Yes but from what I saw, some users may not be able to view the images.
LainaaBut the facts remain that you shouldn't block on blank referrer alone unless you can afford to lose a lot of users who are behind corporate or ISP caching proxies, and that serious protection against bandwidth leeching requires a script/cookies solution.
from: Webmasterworld (http://www.webmasterworld.com/forum92/2934.htm)
I don't really want to block anyone but save the CPU usage because of the way SMF hosts the images.

I'm saying that you block everything except blank referrers and your own site.
Otsikko: Re: Hot linking = danger?
Kirjoitti: chadon - maaliskuu 14, 2008, 08:04:58 IP
OK. I don't know anything about it but I'll probably find the answer on Google. Thanks.
Otsikko: Re: Hot linking = danger?
Kirjoitti: forumnoob - maaliskuu 17, 2008, 01:40:37 AP
Lainaus käyttäjältä: H - maaliskuu 14, 2008, 07:01:58 IP
Lainaus käyttäjältä: chadon - maaliskuu 14, 2008, 05:59:24 IP
Yes but from what I saw, some users may not be able to view the images.
LainaaBut the facts remain that you shouldn't block on blank referrer alone unless you can afford to lose a lot of users who are behind corporate or ISP caching proxies, and that serious protection against bandwidth leeching requires a script/cookies solution.
from: Webmasterworld (http://www.webmasterworld.com/forum92/2934.htm)
I don't really want to block anyone but save the CPU usage because of the way SMF hosts the images.

I'm saying that you block everything except blank referrers and your own site.


No, thats NOT what he wants.

What he needs to do is turn of attachment encryption AND ensure that his attachments & avatar folders are in a web accessible area.


thats easy enough to do via the admin control panel