Remove Ad, Sign Up
Register to Remove Ad
Register to Remove Ad
Remove Ad, Sign Up
Register to Remove Ad
Register to Remove Ad
Signup for Free!
-More Features-
-Far Less Ads-
About   Users   Help
Users & Guests Online
On Page: 1
Directory: 2 & 168
Entire Site: 9 & 1120
Page Staff: pokemon x, pennylessz, Barathemos, tgags123, alexanyways, supercool22, RavusRat,
04-25-24 09:23 PM

Thread Information

Views
591
Replies
4
Rating
1
Status
CLOSED
Thread
Creator
leod
11-15-16 12:36 PM
Last
Post
Pokemonfan1000
11-16-16 03:06 PM
Additional Thread Details
Views: 479
Today: 0
Users: 16 unique
Last User View
06-08-17
Congo!

Thread Actions

Thread Closed
New Thread
New Poll
Order
 

Uploading non-image files to the Photo Album

 

11-15-16 12:36 PM
leod is Offline
| ID: 1314567 | 439 Words

leod
Level: 23


POSTS: 99/100
POST EXP: 9291
LVL EXP: 65002
CP: 454.2
VIZ: 6992

Likes: 1  Dislikes: 0
Hope this is the right place to post this.
Basically, you can rename any file to .png and upload it to vizzed's Photo Album, there's no verification for it actually being an image as far as I can tell (which honestly is a very quick fix).

I've been using this for the past 2-3 years to use external css/php in my layouts, by uploading a .css file with contents like these to the Photo Album, renamed to .png (as can be seen here) and then @import'ing the Photo Album image through a relative link instead of an absolute one, which the URL filter can't detect. Meaning that I just changed the URL from "https://www.vizzed.com/boards/../smd/photo_album_pics/fullsize/281180-1479155328.png" to "/boards/../smd/photo_album_pics/fullsize/281180-1479155328.png", which browsers will look for on the current domain (eg vizzed.com).
The .css file it imports also executes some php on my server, allowing that effect on my layout where the background colors are different on every refresh (and the star tilts slightly differently). This isn't dangerous to vizzed at all since the php is running on my server, not vizzed's, so don't worry. Some other sites that allow for layouts allow this by default, that's how safe it is.
To check the code in the photo I uploaded, just save it to your desktop and rename it to .css or .txt and open it in a text editor.

As sort of a relief, I did try to upload and run php on vizzed using this, but I couldn't get that to work. This is the file I tried to mess with for the record, you can save it just like the earlier file and check out the code, it's just very simple css output.
I didn't really try much of anything else because I figure after the last time we managed to shut the site down you patched out javascript execution and if vizzed doesn't use php then I'd just waste my time trying to figure out what else, but still it might be wise to fix the uploader to actually verify images, just in case.

(edit: This below stuff actually doesn't work because while my layout shows up in the layout editor and during thread previews, it doesn't actually work when viewing a thread, so nevermind that!)
Fun fact: If you click this link, my layout will actually start animating a lot more. You can't put links in signatures on vizzed, so I couldn't put that anywhere, but I figured I'd mention it here to show what kind of stuff remote php enables. (clicking it again undoes it)
Again, harmless because the php is running on my server and not vizzed.
Hope this is the right place to post this.
Basically, you can rename any file to .png and upload it to vizzed's Photo Album, there's no verification for it actually being an image as far as I can tell (which honestly is a very quick fix).

I've been using this for the past 2-3 years to use external css/php in my layouts, by uploading a .css file with contents like these to the Photo Album, renamed to .png (as can be seen here) and then @import'ing the Photo Album image through a relative link instead of an absolute one, which the URL filter can't detect. Meaning that I just changed the URL from "https://www.vizzed.com/boards/../smd/photo_album_pics/fullsize/281180-1479155328.png" to "/boards/../smd/photo_album_pics/fullsize/281180-1479155328.png", which browsers will look for on the current domain (eg vizzed.com).
The .css file it imports also executes some php on my server, allowing that effect on my layout where the background colors are different on every refresh (and the star tilts slightly differently). This isn't dangerous to vizzed at all since the php is running on my server, not vizzed's, so don't worry. Some other sites that allow for layouts allow this by default, that's how safe it is.
To check the code in the photo I uploaded, just save it to your desktop and rename it to .css or .txt and open it in a text editor.

As sort of a relief, I did try to upload and run php on vizzed using this, but I couldn't get that to work. This is the file I tried to mess with for the record, you can save it just like the earlier file and check out the code, it's just very simple css output.
I didn't really try much of anything else because I figure after the last time we managed to shut the site down you patched out javascript execution and if vizzed doesn't use php then I'd just waste my time trying to figure out what else, but still it might be wise to fix the uploader to actually verify images, just in case.

(edit: This below stuff actually doesn't work because while my layout shows up in the layout editor and during thread previews, it doesn't actually work when viewing a thread, so nevermind that!)
Fun fact: If you click this link, my layout will actually start animating a lot more. You can't put links in signatures on vizzed, so I couldn't put that anywhere, but I figured I'd mention it here to show what kind of stuff remote php enables. (clicking it again undoes it)
Again, harmless because the php is running on my server and not vizzed.
Trusted Member

Affected by 'Laziness Syndrome'

Registered: 09-30-12
Location: Germany
Last Post: 2718 days
Last Active: 1193 days

(edited by leod on 11-15-16 02:40 PM)     Post Rating: 1   Liked By: jlove92,

11-15-16 12:47 PM
jlove92 is Offline
| ID: 1314571 | 55 Words

jlove92
Level: 57


POSTS: 739/880
POST EXP: 90012
LVL EXP: 1456101
CP: 6193.2
VIZ: 247087

Likes: 0  Dislikes: 0
leod : You sir have just earned the most useful user award in my book . I am adding this to my favorite and trying this on my next layout. I've had problems uploading gifs due to size limitation which when I reduce on Photoshop makes the graphics look too pixy. Have you had this problem?
leod : You sir have just earned the most useful user award in my book . I am adding this to my favorite and trying this on my next layout. I've had problems uploading gifs due to size limitation which when I reduce on Photoshop makes the graphics look too pixy. Have you had this problem?
Trusted Member
Queen of Hearts


Affected by 'Laziness Syndrome'

Registered: 10-19-15
Location: Florida
Last Post: 1101 days
Last Active: 545 days

11-15-16 02:33 PM
leod is Offline
| ID: 1314586 | 116 Words

leod
Level: 23


POSTS: 100/100
POST EXP: 9291
LVL EXP: 65002
CP: 454.2
VIZ: 6992

Likes: 0  Dislikes: 0
jlove92 : Oh this wasn't meant to be some kind of tip, especially since it seems my layout doesn't actually show up in threads because of this exploit being used anymore. I posted this more so that it can be fixed, since it's clearly unintentional.

It used to work just fine, and it still does show up in the layout editor and when I preview a post, but inside threads it appears to be thrown out (as can be seen in the two posts in this thread) (a moderator can probably check the layout I have equipped right now and see that it works in the layout editor just fine?).
Interesting! But the bug is still there!
jlove92 : Oh this wasn't meant to be some kind of tip, especially since it seems my layout doesn't actually show up in threads because of this exploit being used anymore. I posted this more so that it can be fixed, since it's clearly unintentional.

It used to work just fine, and it still does show up in the layout editor and when I preview a post, but inside threads it appears to be thrown out (as can be seen in the two posts in this thread) (a moderator can probably check the layout I have equipped right now and see that it works in the layout editor just fine?).
Interesting! But the bug is still there!
Trusted Member

Affected by 'Laziness Syndrome'

Registered: 09-30-12
Location: Germany
Last Post: 2718 days
Last Active: 1193 days

11-15-16 02:44 PM
jlove92 is Offline
| ID: 1314588 | 71 Words

jlove92
Level: 57


POSTS: 749/880
POST EXP: 90012
LVL EXP: 1456101
CP: 6193.2
VIZ: 247087

Likes: 0  Dislikes: 0
leod : There's always a way to get around things specially when coding is involved. I just trying doing what you described and get the same error. I was hoping to find a way around it. I got two layout and hoped this will help me get them finished and working. 
I don't know maybe a new coding on these pages keeps it from working whereas layout editor may have old codes?
leod : There's always a way to get around things specially when coding is involved. I just trying doing what you described and get the same error. I was hoping to find a way around it. I got two layout and hoped this will help me get them finished and working. 
I don't know maybe a new coding on these pages keeps it from working whereas layout editor may have old codes?
Trusted Member
Queen of Hearts


Affected by 'Laziness Syndrome'

Registered: 10-19-15
Location: Florida
Last Post: 1101 days
Last Active: 545 days

11-16-16 03:06 PM
Pokemonfan1000 is Offline
| ID: 1314844 | 130 Words

Pokemonfan1000
Level: 58


POSTS: 321/957
POST EXP: 48442
LVL EXP: 1550898
CP: 2097.1
VIZ: 2100

Likes: 0  Dislikes: 0
leod : I'll summon David for you.

Davideo7 : (Content hidden from non-administrators!)
leod : I'll summon David for you.

Davideo7 : (Content hidden from non-administrators!)
Perma Banned
The only user so far in the 309 and 563 area codes currently active on any acmlm based board (save for smwcentral.net and Lespna1) If you want to dispute this claim, feel free to PM me.


Affected by 'Laziness Syndrome'

Registered: 10-20-16
Location: Quad Cities
Last Post: 2495 days
Last Active: 2494 days

(edited by Pokemonfan1000 on 11-16-16 03:23 PM)    

Links

Page Comments


This page has no comments

Adblocker detected!

Vizzed.com is very expensive to keep alive! The Ads pay for the servers.

Vizzed has 3 TB worth of games and 1 TB worth of music.  This site is free to use but the ads barely pay for the monthly server fees.  If too many more people use ad block, the site cannot survive.

We prioritize the community over the site profits.  This is why we avoid using annoying (but high paying) ads like most other sites which include popups, obnoxious sounds and animations, malware, and other forms of intrusiveness.  We'll do our part to never resort to these types of ads, please do your part by helping support this site by adding Vizzed.com to your ad blocking whitelist.

×