Inserting Smileys - PHPIDS

Ok, I know we have discussed this before and how PHPIDS just LOVES smileys. So here is my question. How do we get our sites to allow smileys without having to bump our impact levels to 100+ ? My daughter posting a blog regarding how she was doing in college and I believe she added a smiley in it as well. This blocked her completely and send me an email with a total impact of 98..

Oh yeah, I also should mention that she was logged in using her Facebook credentials.

If it's disabling the ability to add smileys, then fine, but I would prefer a fix. If we are going to allow editors that will give the member an option to insert a smiley, then we should allow it without a PA email AND block.

Chris

Nothing to see here
Quote · 16 Dec 2009

As an option it is possible to disable PHPIDS at all, by settings all security impacts to -1

Rules → http://www.boonex.com/terms
Quote · 16 Dec 2009

If the security impact has to be set so high for routine member interactions with the site, how will PHPIDS ever know what a real attack is?


A smiley involves nothing more than an img tag, and I've never heard of a hacker clever enough to take a site down with the img tag.  There has got to be something fundamentally wrong with the way PHPIDS is integrated.

My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 16 Dec 2009

I understand that we can disable PHPIDS by changing the values to a -1 (negative) value, however is this the only way to fix this? I kinda like the fact that it will block actual spammers.

Chris

Nothing to see here
Quote · 18 Dec 2009

It would be nice if it could tell the difference between spammers and legit members.

My opinions expressed on this site, in no way represent those of Boonex or Boonex employees.
Quote · 18 Dec 2009

Oh I totally agree HoustonLively, I mean as I stated before, if we are going to allow the members to do something, then let them do it. No need to block it.

Is there no other option besides PHPIDS that can help secure Dolphin without disabling some of its "normal" features?

Chris

Nothing to see here
Quote · 18 Dec 2009
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.