Show HN: UrlRoulette – Pass a URL to the next visitor
101–110 of 143 posts
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#102Earlier quoted context omitted.
That's odd. UrlRoulette does some sanity checking on the content of the URL. Thank you for this bug report!
https://cryptowat.ch fails too. seems to fail at very basic URL parsing.
Please upgrade to a supported browser to get a reCAPTCHA challenge.
Alternatively if you think you are getting this page in
error, please check your internet connection and reload.
I could reload to infinity, this would not fix this broken website or change the useless error message.Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#103Potential for XSS attacks is fairly large. Be careful out there.
Having uMatrix and NoScript addons on firefox may reduce some risks, also in general web browsing
Once you've enabled cloudflare, anything can happen.
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#104I really struggled with your captcha. I had to solve 10 screens of images, it was very time-consuming and tedious.
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#105Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#106Earlier quoted context omitted.
They get removed.
No, you put them in a database. Don't lie to us.
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#107I just got urlceptioned back to this page :)
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#108Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#109Is this some sort of infosec performance art? This seems extremely inadvisable for users or the person running the site. What if someone posts something illegal in the jurisdiction of the viewer or a link to a site with an embedded exploit?
It's no more dangerous than clicking on any shortened URL.
Re: Show HN: UrlRoulette – Pass a URL to the next visitor
#110It probably goes without saying, but you should definitely use some kind of sandboxed browser/session if you want to try this. One annoying URL someone could submit is superlogout.com, which uses logout CSRF to log you out of a whole ton of websites at once. However, I couldn't get it to work in a private tab, because apparently the invisible captcha fails.
Luckily I'm immune to this as I don't have an account on any of these websites but one and I only log there once every 2 years for about 5 minutes.