Missing iframes

Reblogger
Home Builder with The Flooring Girl

In case you missed this. I am not a happy camper right now.

this impacts you if you have any of the following:

- embedded google maps

- videos that were manually embedded

- reabird listing

 I have 63 posts to edit.  I've done 10 so far.

It has come to our attention that a few of you may be missing iframed HTML from your blog posts.  We've estimated that less than 1,000 members have been affected.  Only those members who have manually embedded an iframe in their posts between January 9th 2013 and June 20th may have been affected.  No profiles or signatures were affected.

An iframe is an HTML document embedded within another HTML document.  So a video or widget embedded on a blog post could be an iframe.  Essentially it could look something like this: <iframe id="ifrm" src="demo.html"></iframe>

Here's what happened; in January we introduced a new software library, Loofah, into AR to prevent Cross-site scripting. Cross-site scripting is a type of code found in Web applications that allows code from one site to display on another site. This type of code is often exploited by spammers and evil types and the goal was to shore up the security of ActiveRain.

When we released the deploy last week, it caused some blog posts to be stripped of their iframes.  Loofah had been overly aggressive; stripping iframes from blogs posts.  You didn't immediately see this because what was being written into our memory cache was different from what was being permanently stored in the database.  Once the posts aged out of the cache, it was retrieved from the database and displayed without its iframe.

We are very sorry and sincerely apologize for this situation.

The good news is we have replaced much of the lost information so most of you won't even miss a beat. Another positive is that IT has fixed Loofah so it will not attack iframes going forward.  This new Loofah has been tested and verified with our IT team.  For those members that are missing a video or other iframe piece within your blog post, you'll need to enter it once again and can do so in 4 steps.

We have done our best to think outside of the box and retrieve as much of the lost footage as possible.  We sincerely apologize for this situation and inconvenience to those affected.

 

 



Keep Up In the Rain!

ActiveRain FacebookActiveRain TwitterActiveRain YouTubeActiveRain Google+ActiveRain LinkedIn

Comments (6)

Liz and Bill Spear
RE/MAX Elite 513.520.5305 www.LizTour.com - Mason, OH
RE/MAX Elite Warren County OH (Cincinnati/Dayton)

Debbie, Guess I'm going to have to go back and check our posts just to be safe.  I had one the other day I noticed missing the Google map and didn't make the connection WHY it had went poof.  Hopefully not too many impacted, kind of tedious to go correct them all.

Jun 28, 2013 09:47 AM
Debbie Gartner
The Flooring Girl - White Plains, NY
The Flooring Girl & Blog Stylist -Dynamo Marketers

Bliz - right, I think a lot don't realize this is impacting them.  Yes, tedious for sure.

Jun 28, 2013 10:11 AM
DeeDee Riley
Lyon Real Estate - El Dorado Hills CA - El Dorado Hills, CA
Realtor - El Dorado Hills & the Surrounding Areas

Hi Debbie,

 

I wonder if this is why there is no wrapping of text on my posts and the frames keep going and going.  Not happy!

Jun 28, 2013 10:25 AM
Ralph Janisch ABR CRS Broker
Janisch & Co. - Conroe, TX
Selling Northwest Houston to good people like you!

Ahhhh.... the trials and tribulations of a programmer.  Sometimes it bites us all on the butt.  I'm just glad to see it was caught and they do assume blame for the problem.  As long as it doesn't happen again.  We should be happy!

Jun 28, 2013 01:57 PM
Debbie Gartner
The Flooring Girl - White Plains, NY
The Flooring Girl & Blog Stylist -Dynamo Marketers

DeeDee - Me either.

Steven - I didn't even realize it until they posted.  I've gotten up to Feb 9th now.

Jeanne & Ralph - Yes, glad that they caught and fixed it. But, it's a lot of rework for many of us.

Jun 28, 2013 08:03 PM

What's the reason you're reporting this blog entry?

Are you sure you want to report this blog entry as spam?