Hacker Poesy
  • FAQ
  • Login
  • Public

    • Public
    • Groups
    • Recent tags
    • Popular
    • Directory

Conversation:

Notices

  1. MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 07:58:20 EST MMN-o ✅⃠ MMN-o ✅⃠
    Remote profile options...
    • hiker
    @hiker Haha, whut. Where?
    Sunday, 15-Feb-2015 07:58:20 EST from social.umeahackerspace.se permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:08:33 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      • hiker
      @hiker Oh, that's really weird. Saw on your site now. Those fields should be escaped properly.
      Sunday, 15-Feb-2015 08:08:33 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:17:33 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      • hiker
      Uhm. !gnusocial - the #Textile plugin has this code:
      $tmp = str_replace('"','"',$notice->rendered);

      I would not trust the #Textile plugin to be safe from #XSS attacks. I guess I could change my fullname to something like: Mikael " onclick="javascript:alert('butt');" title="pwn
      Sunday, 15-Feb-2015 08:17:33 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:22:04 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      • hiker
      I wonder if this does it. I'm not very good at #XSS examples :)
      Sunday, 15-Feb-2015 08:22:04 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:24:39 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      • hiker
      Oh I might have to signal it like @mmn @hiker
      Sunday, 15-Feb-2015 08:24:39 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:29:25 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      @hiker click my name here: @mmn and then hurry off to disable the #Textile plugin until @bavatar@sn.diekershoff.de patches it.
      !gnusocial !sn !snbug etc. to anyone who runs the thirdparty #Textile plugin.
      Sunday, 15-Feb-2015 08:29:25 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:30:29 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      ^- @tobias@f.diekershoff.de if that's where you're listening for notices. It's an XSS security issue in the #Textile plugin.
      Sunday, 15-Feb-2015 08:30:29 EST permalink
    • MMN-o ✅⃠ (mmn)'s status on Sunday, 15-Feb-2015 08:52:36 EST MMN-o ✅⃠ MMN-o ✅⃠
      Remote profile options...
      • hiker
      @hiker Yes because that's how it is saved in the database. But you won't get any new such notices (as GNU social filters the html and escapes stuff propetly - what Textile does is bypassing that instead of adapting it)
      Sunday, 15-Feb-2015 08:52:36 EST permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Hacker Poesy is a GNU social hub. It runs version 1.1.3-beta3, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Hacker Poesy content and data are available under the Creative Commons Attribution 3.0 license.

Switch to mobile site layout.