GhettoWebmaster likes
16 years ago
giving the Plurk staff stuff to fix. :-P
latest #27
pkrumins
16 years ago
more more!
GhettoWebmaster says
16 years ago
hehe... I imagine there is a bunch more. Just need to get all this script kiddie stuff out of the way first.
pkrumins says
16 years ago
fixed your last discovery at register page.
立即下載
pkrumins says
16 years ago
had some silliness going on that element's innerHTML was set to form's content.
pkrumins says
16 years ago
previously i had just fixed to escape HTML in the form itself.
GhettoWebmaster will
16 years ago
dig some more later. In the meantime, you guys should work on limiting cookie/referrer-less traffic to prevent DOS attacks and profile...
GhettoWebmaster
16 years ago
...view count gaming.
pkrumins
16 years ago
good thinking!
GhettoWebmaster says
16 years ago
the chick with the top profile views on Plurk right now obviously gamed many of those. My profile views are proof of concept on that.
pkrumins
16 years ago
yep, i noticed that
GhettoWebmaster says
16 years ago
YouTube had a big problem with video count view gaming. Not sure if they ever fixed it 100 percent. I know they did enough to keep the...
pkrumins
16 years ago
we have a framework for rate-limiting
GhettoWebmaster
16 years ago
...skiddies away though
pkrumins
16 years ago
yeh
pkrumins
16 years ago
we rate limited logins and registrations recently
pkrumins
16 years ago
so we can just reuse that stuff for profile views as well.
GhettoWebmaster
16 years ago
would have to see how your rate limiting is setup to really say much.
GhettoWebmaster
16 years ago
"we have a XSS lib in place" - amix
pkrumins
16 years ago
i am gonna query amix for more details about it
GhettoWebmaster
16 years ago
^^^ Thinks the rate-limiting out of the box solution might also be screwy based on that.
pkrumins
16 years ago
i know we added xss protection right at template level
pkrumins
16 years ago
but i did not examine it as i was working on something else
GhettoWebmaster thinks
16 years ago
you guys also might want to talk to Steadfast about upgrading nginx. The change logs since 0.6.32 have a bunch of stuff in them. ;-)
pkrumins
16 years ago
we control the servers ourselves
GhettoWebmaster
16 years ago
Sweet...
amix
16 years ago
thanks a lot for your suggestions Loren. we appreciate it
GhettoWebmaster says
16 years ago
np
back to top