GhettoWebmaster likes
15 years ago
giving the Plurk staff stuff to fix. :-P
latest #27
pkrumins
15 years ago
more more!
GhettoWebmaster says
15 years ago
hehe... I imagine there is a bunch more. Just need to get all this script kiddie stuff out of the way first.
pkrumins says
15 years ago
fixed your last discovery at register page.
立即下載
pkrumins says
15 years ago
had some silliness going on that element's innerHTML was set to form's content.
pkrumins says
15 years ago
previously i had just fixed to escape HTML in the form itself.
GhettoWebmaster will
15 years ago
dig some more later. In the meantime, you guys should work on limiting cookie/referrer-less traffic to prevent DOS attacks and profile...
GhettoWebmaster
15 years ago
...view count gaming.
pkrumins
15 years ago
good thinking!
GhettoWebmaster says
15 years ago
the chick with the top profile views on Plurk right now obviously gamed many of those. My profile views are proof of concept on that.
pkrumins
15 years ago
yep, i noticed that
GhettoWebmaster says
15 years ago
YouTube had a big problem with video count view gaming. Not sure if they ever fixed it 100 percent. I know they did enough to keep the...
pkrumins
15 years ago
we have a framework for rate-limiting
GhettoWebmaster
15 years ago
...skiddies away though
pkrumins
15 years ago
yeh
pkrumins
15 years ago
we rate limited logins and registrations recently
pkrumins
15 years ago
so we can just reuse that stuff for profile views as well.
GhettoWebmaster
15 years ago
would have to see how your rate limiting is setup to really say much.
GhettoWebmaster
15 years ago
"we have a XSS lib in place" - amix
pkrumins
15 years ago
i am gonna query amix for more details about it
GhettoWebmaster
15 years ago
^^^ Thinks the rate-limiting out of the box solution might also be screwy based on that.
pkrumins
15 years ago
i know we added xss protection right at template level
pkrumins
15 years ago
but i did not examine it as i was working on something else
GhettoWebmaster thinks
15 years ago
you guys also might want to talk to Steadfast about upgrading nginx. The change logs since 0.6.32 have a bunch of stuff in them. ;-)
pkrumins
15 years ago
we control the servers ourselves
GhettoWebmaster
15 years ago
Sweet...
amix
15 years ago
thanks a lot for your suggestions Loren. we appreciate it
GhettoWebmaster says
15 years ago
np
back to top