Login
Sign Up For Free
English
中文 (繁體)
中文 (香港)
中文 (简体)
日本語
Filipino
Bahasa Indonesia
Bahasa Melayu
Pусский
Português (Brasil)
Magyar
Français
Español
Deutsch
Čeština
العربية
Català
Dansk
Ελληνικά
فارسی
Suomi
Gaeilge
Hindi
עברית
Hrvatski
Italiano
Norsk bokmål
Nederlands
한국어
Polski
Română
Slovenský
Svenska
Türkçe
українська
беларуская
ไทย
Standard view
GhettoWebmaster
likes
15 years ago
giving the Plurk staff stuff to fix.
latest #27
pkrumins
15 years ago
more more!
GhettoWebmaster
says
15 years ago
hehe... I imagine there is a bunch more. Just need to get all this script kiddie stuff out of the way first.
pkrumins
says
15 years ago
fixed your last discovery at register page.
立即下載
pkrumins
says
15 years ago
had some silliness going on that element's innerHTML was set to form's content.
pkrumins
says
15 years ago
previously i had just fixed to escape HTML in the form itself.
GhettoWebmaster
will
15 years ago
dig some more later. In the meantime, you guys should work on limiting cookie/referrer-less traffic to prevent DOS attacks and profile...
GhettoWebmaster
15 years ago
...view count gaming.
pkrumins
15 years ago
good thinking!
GhettoWebmaster
says
15 years ago
the chick with the top profile views on Plurk right now obviously gamed many of those. My profile views are proof of concept on that.
pkrumins
15 years ago
yep, i noticed that
GhettoWebmaster
says
15 years ago
YouTube had a big problem with video count view gaming. Not sure if they ever fixed it 100 percent. I know they did enough to keep the...
pkrumins
15 years ago
we have a framework for rate-limiting
GhettoWebmaster
15 years ago
...skiddies away though
pkrumins
15 years ago
yeh
pkrumins
15 years ago
we rate limited logins and registrations recently
pkrumins
15 years ago
so we can just reuse that stuff for profile views as well.
GhettoWebmaster
15 years ago
would have to see how your rate limiting is setup to really say much.
GhettoWebmaster
15 years ago
"we have a XSS lib in place" - amix
pkrumins
15 years ago
i am gonna query amix for more details about it
GhettoWebmaster
15 years ago
^^^ Thinks the rate-limiting out of the box solution might also be screwy based on that.
pkrumins
15 years ago
i know we added xss protection right at template level
pkrumins
15 years ago
but i did not examine it as i was working on something else
GhettoWebmaster
thinks
15 years ago
you guys also might want to talk to Steadfast about upgrading nginx. The change logs since 0.6.32 have a bunch of stuff in them.
pkrumins
15 years ago
we control the servers ourselves
GhettoWebmaster
15 years ago
Sweet...
amix
15 years ago
thanks a lot for your suggestions Loren. we appreciate it
GhettoWebmaster
says
15 years ago
np
back to top
delete
reply
edit
cancel
cancel