educational

Protecting Your Content

I believe that if someone pulls an image off of your server, plants it on his, and then displays it, that he is breaking the law. But if a user posts the URL to your image in a chat room, USENET Group or BBS of some sort, it is the webmaster of the content that is at fault.

You are in control of how your content is displayed. If it is being abused it is your fault. New webmasters often threaten legal action over this form of piracy, but if you leave the bank vault door open, don't be surprised if all of your money is gone in the morning.

On most http servers there is a way to prevent serving your content to off-site URLs, for example, posting my.site.com/dirtypic.jpg to chatroomxxx.com/sexychat.html. You can stop this by reading your web server docs. If it's your ISP's web server it's that much easier to tell him what to do. If it's your own web server, then you must do something about the situation yourself.

In order to protect your content from hot-linking under Apache, you first need to have mod_rewrite enabled (either compiled in, or linked dynamically), and then you need to add the following to your .htaccess file:

[CODE] RewriteEngine on RewriteCond %{HTTP_REFERER} !^$ RewriteCond %{HTTP_REFERER} !^https://.*(chatropolis.com|interfun.net|XXX.XX.XXX.XX).*$ [NC] RewriteRule .*.(gif|jpg|GIF|JPG)$ /images/can_not_display_image.jpg [/CODE]

This is what we do at Chatropolis to prevent users of our service from stealing our bandwidth. The surfer will have to be reading the actual page on our site to see the image, or they will get a nasty image informing them of the theft.

Here is an explanation of the cryptic lines in the config code above: The first line turns on the rewriting for this config. The second and third lines specify conditions under which the rule will match – in this case if the referrer isn't blank and doesn't contain "chatropolis.com", "interfun.net", or "XXX.XX.XXXX.XX" (case insensitive because of [NC]). The last line specifies a regexp to do the actual rewriting. In this case, any URL with gif or jpg gets rewritten to read /images/can_not_display_image.jpg.

I assume that if you are not using Apache that the process should be somewhat similar for your server. If it is impossible to do with your server, then it's time to think about changing servers – at least if you plan on staying in any type of web site-based business for long.

For a UNIX pro, implementing this protection takes a few minutes. For a novice, it might take a few hours of getting to know your server, but when finished, you will have fixed a potential problem forever, and there is something about knowing it's fixed forever that will make you sleep better.

Alternatively, many webmasters put a small unobtrusive image stamp on their content, and get literally 1000's of dollars of advertising for free. A webmaster that does this has even reported that our users convert like crazy, and while I don't know how true that is, the free advertising can't hurt.

The moral of the story is that you're responsible for your content, and once you hear that horrible word "Retainer" from your lawyer, spending a little amount of time to improve content security will look a lot more attractive. So if you don't want to leave the vault open, take my advice and close it yourself, or take advantage of the advertising. The worst thing that you could do is nothing, because on top of losing money, you will not make any extra from the hard work of unscrupulous users.

This article was written with the technical help of Pedro Margate our Sysad at Chatropolis.com. You can check out Pedro at www.terrapodsoftware.com.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

How to Thwart Holiday Fraudsters With Finesse

The holiday season is a prime time for shopping. Unfortunately, it’s also peak season for credit card fraud. With increased transactions both online and in-store, fraudsters have more opportunities to exploit vulnerabilities — and they are getting better at it every day.

Jonathan Corona ·
opinion

How to Halt Hackers as Fraud Attacks Rise

For hackers, it’s often a game of trial and error. Bad actors will perform enumeration and account testing, repeating the same test on a system to look for vulnerabilities — and if you are not equipped with the proper tools, your merchant account could be the next target.

Cathy Beardsley ·
profile

VerifyMy Seeks to Provide Frictionless Online Safety, Compliance Solutions

Before founding VerifyMy, Ryan Shaw was simply looking for an age verification solution for his previous business. The ones he found, however, were too expensive, too difficult to integrate with, or failed to take into account the needs of either the businesses implementing them or the end users who would be required to interact with them.

Alejandro Freixes ·
opinion

How Adult Website Operators Can Cash in on the 'Interchange' Class Action

The Payment Card Interchange Fee Settlement resulted from a landmark antitrust lawsuit involving Visa, Mastercard and several major banks. The case centered around the interchange fees charged to merchants for processing credit and debit card transactions. These fees are set by card networks and are paid by merchants to the banks that issue the cards.

Jonathan Corona ·
opinion

It's Time to Rock the Vote and Make Your Voice Heard

When I worked to defeat California’s Proposition 60 in 2016, our opposition campaign was outspent nearly 10 to 1. Nevertheless, our community came together and garnered enough support and awareness to defeat that harmful, misguided piece of proposed legislation — by more than a million votes.

Siouxsie Q ·
opinion

Staying Compliant to Avoid the Takedown Shakedown

Dealing with complaints is an everyday part of doing business — and a crucial one, since not dealing with them properly can haunt your business in multiple ways. Card brand regulations require every merchant doing business online to have in place a complaint process for reporting content that may be illegal or that violates the card brand rules.

Cathy Beardsley ·
opinion

Girlsway Celebrates a Decade of Acclaimed Sapphic Erotica

When Girlsway launched back in 2014, Bree Mills had a plan. As head of production for Gamma Entertainment, she set out to up the stakes of all-girl content with the new imprint — and to continually, proactively reinvent the brand and its offerings along the way.

Alejandro Freixes ·
profile

WIA Profile: Patricia Ucros

Born in Bogota, Colombia, Ucros graduated from college with a degree in education. She spent three years teaching third grade, which she enjoyed a lot, before heeding her father’s advice and moving to South Florida.

Women In Adult ·
opinion

Creating Payment Redundancies to Maximize Payout Uptime

During the global CrowdStrike outage that took place toward the end of July, a flawed software update brought air travel and electronic commerce to a grinding halt worldwide. This dramatically underscores the importance of having a backup plan in place for critical infrastructure.

Jonathan Corona ·
opinion

The Need for Minimal Friction in Age Verification Technology

In the adult sector, robust age assurance, comprised of age verification and age estimation methods, is critical to ensuring legal compliance with ever-evolving regulations, safeguarding minors from inappropriate content and protecting the privacy of adults wishing to view adult content.

Gavin Worrall ·
Show More