Earlier quoted context omitted.
This is the "Lucky Pierre" type of lucky. If you don't know what that is, you might not want to search it.
None of these seem particularly horrifying? https://en.wikipedia.org/wiki/Lucky_Pierre
Using Goatse to Stop App Theft
401–410 of 464 posts
Re: Using Goatse to Stop App Theft
#402Earlier quoted context omitted.
Awesome - and the first time I've actually had someone "post" on my site.
You're welcome. :D The client-side XSS is mostly harmless (assuming you don't have any other sensitive services running with cookies scoped to this domain), although it's technically a persistent XSS, which means it could be indexed by search engines. But is there a server-side component to this? I noticed that the "disclaimer" is added in the source returned by the server, so I assume there is some code that checks…
TBH I haven't thought about most of these things. Nobody typically reads my blogs when I've made them before and this is likely the only interest it will get for quite a while.
Re: Using Goatse to Stop App Theft
#403Ah, I had a similar idea. There were too many bots or vulnerability scanners hitting /wp-admin.php on my blog. It was flooding my access logs with 404s because I don't rock wordpress. Irksome stuff. So I threw up a little 'surprise' for the ahem penetration testers ahem , if you feel brave: https://www.thran.uk/wp-login.php
Re: Using Goatse to Stop App Theft
#404Re: Using Goatse to Stop App Theft
#405Earlier quoted context omitted.
> The author is aware. Since the website is vulnerable to XSS, you could inject a script that removes the disclaimer.
100%. poc: https://joshcsimmons.com/post/eNqzKU4uyiwosUvJTy7NTc0r0UtPLX...
Re: Using Goatse to Stop App Theft
#406Earlier quoted context omitted.
You're welcome. :D The client-side XSS is mostly harmless (assuming you don't have any other sensitive services running with cookies scoped to this domain), although it's technically a persistent XSS, which means it could be indexed by search engines. But is there a server-side component to this? I noticed that the "disclaimer" is added in the source returned by the server, so I assume there is some code that checks…
I've just added some defensive programming to the site. Sorry to say. Appreciate that you hacked it with your image onerror, pretty clever. TBH I haven't thought about most of these things. Nobody typically reads my blogs when I've made them before and this is likely the only interest it will get for quite a while.
Can't promise I won't circumvent it when I've got some time...
Re: Using Goatse to Stop App Theft
#407Earlier quoted context omitted.
> Anything can be generated here. You could even host your own blog that uses my website as a renderer if you really wanted to. It supports markdown. > Every post that I want to publicly claim authorship of lives at the root of this site. If you are reading a post that I have claimed it will look like this page. Posts of unknown authorship have a disclaimer at the top of the page. https://joshcsimmons.com/post/H4sIAA…
>Posts of unknown authorship have a disclaimer at the top of the page. Problem is, the posts can contain elements. So it's easy to just write a little JavaScript that removes the disclaimer at the top. See this hastily-made, immature example of mine: https://joshcsimmons.com/post/H4sIABO8LmUC/3VT0W7aQBB85yu2QV... As it stands, this really isn't the most secure system. Something much more malicious could be injected i…
Re: Using Goatse to Stop App Theft
#408Earlier quoted context omitted.
>Posts of unknown authorship have a disclaimer at the top of the page. Problem is, the posts can contain elements. So it's easy to just write a little JavaScript that removes the disclaimer at the top. See this hastily-made, immature example of mine: https://joshcsimmons.com/post/H4sIABO8LmUC/3VT0W7aQBB85yu2QV... As it stands, this really isn't the most secure system. Something much more malicious could be injected i…
Shouldn’t it be “shat”? Either way, considering the submission we’re commenting on, the author of the blog may appreciate your humour.
Re: Using Goatse to Stop App Theft
#409Earlier quoted context omitted.
A couple of years ago, the main submarine link connecting my country to the internet was damaged, and internet basically slowed to a crawl for a day. Could barely open anything. But Netflix was running at full HD with no problem. So they must have had local cache's with the ISPs.
Very likely. Netflix has a program where they ship edge cache appliances to ISPs free of charge.
Re: Using Goatse to Stop App Theft
#410* The people you're hurting with the goatse image are mostly not the people wrapping your game in an iframe, but rather the people playing games on the game aggregator sites. Probably includes many teenagers and children.
* The game aggregator sites are bringing your game to a wider audience. For gamers who don't know the name of a specific game they want to play, it's nice to be able to browse through a directory of games. The game aggregator sites aren't competing with you in terms of Google search results, they're adding your game to their collection and sharing their collection with everyone. Yes, they're supported by advertising, but I'd argue game aggregator sites are still generating a ton of consumer surplus. (For example, many users are blocking ads.)
If you still want to hurt the game aggregator sites for some reason, just include a message on the game loading screen that says "play without ads at sqword.com". Easy.