News | Forum | People | FAQ | Links | Search | Register | Log in
Site Help
This is the forum to ask questions about this website, report things that are broken, request features, etc.

Be sure to check out the FAQ as well.
First | Previous | Next | Last
I AM A FAGGOT! 
HUMP MY RUMP! 
Well... 
I think all issues can be addressed.

First, the misleading URL demonstrated by spirit can be mitigated by making raw URLs look different that anchor tags, using color or other formatting.

Second, the http-based XSS attack spirit showed can be fixed by making the logout button require POST instead of GET.

Third, the javascript-based XSS attacks as demonstrated by czg can be prevented by being stricter about the URL (i.e. requiring http:/ftp: at the beginning) 
I AM A FAGGOT! 
HUMP MY RUMP! 
Rofl 
its not true!!! 
Also... 
i might consider allowing anchor tags only in discussion/news threads, and not in posts. This means our news can look nicer, and anything malicious is easily moderated (since threads are few compared to posts.) 
Lol, Great Link 
Ricky: "sweet deadly white stick" up your rump 
I AM A FAGGOT! 
HUMP MY RUMP! 
 
oh god I am a gullible idiot. 
I AM A FAGGOT! 
HUMP MY RUMP! 
I AM A FAGGOT! 
HUMP MY RUMP! 
Comedy Gold 
 
:) 
Input validation is a thicket of all sorts of horrors. 
I AM A FAGGOT! 
HUMP MY RUMP! 
Oh No... 
Damn, what is this shit !!?? czg: you are the most stupid of us, you damn bastard ! I hate you ! 
I AM A FAGGOT! 
HUMP MY RUMP! 
I AM A FAGGOT! 
HUMP MY RUMP! 
I AM A FAGGOT! 
HUMP MY RUMP! 
I AM A FAGGOT! 
HUMP MY RUMP! 
 
"Hey, nothing happened"
"Hm, still nothing"
"ooooooooooooooooh" 
Czg 
Forgot what I said, Spirit is the winner of this stupidity context without any doubts :P 
This Exploit Is Hilarous... 
but it is now fixed. Anchor tag URLs must start with the ftp, http, or https scheme in order to be converted to clickable links. 
Huzzah For Metlslime !! 
 
And.... 
as a trial, i made it so user-created anchor tags are embedded in square brackets, so that they can be distinguished from raw URLs. We'll see how it feels. Example:

http://www.google.com/ -- raw URL
http://www.goatse.cx/ -- anchor tag 
 
more mapping less cady garden bitches!!! 
Forum Search 
While the Google trick is well-known to all of us, new members or guests seem to get confused by the apparent lack of an integrated search function here (which often results in misplaced posts/threads). Now, what about simply adding another link up there leading to a simple search form that forwards the request to Google with the site:celephais.net/board argument added? 
First | Previous | Next | Last
You must be logged in to post in this thread.
Website copyright © 2002-2024 John Fitzgibbons. All posts are copyright their respective authors.