site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
108
Share Topic
Post a:
Post a:
AuthorAll Replies


justin
Australian
join:1999-05-28
New York, NY
kudos:7
Host:
IPv6
Business Connectiv..
Console/Handheld g..
Home/Office setup ..
Photos of Broadban..

The fix isn't very good

Reading the fix that movabletype.org have done .. well, it doesn't strike me as particularly good. So now they've limited the script to one target address and a short message body?

A spam-bot with a list of N movable type domain names could, in parallel, spam N people per second, even if everyone fixed their script per the recommendation. Ok that isn't as efficient as spamming NxM people per second (the original script allowed lists of people). But it is still possible.

It would be better if movabletype.org put a challenge response token into the loop, so you can't POST to it unless you have done a GET of the form, first, and a delay as well. Better still, remove the ability to enter a custom message (where the advert goes) entirely!

Or just remove the script and do not allow anon users to send links to any email address they like.


trparky
Apple... YUM
Premium,MVM
join:2000-05-24
Cleveland, OH
kudos:1

Me too, the fix is horrible. Basically, the fix shows that they are lazy and that they don't want to fix it the correct way.
--
WedgeAntilles250



nil
Java Geek
join:2000-11-27
kudos:1
Host:
Webmasters and Dev..
Forum Feature Requ..

In all fairness to Ben and Mena I don't think you can call them 'lazy' over a bad fix.. Movable Type is still a terrific tool and still free.. Hopefully they'll have a better fix soon, in the meantime, people should just remove the script altogether. There's no true need for it.
--
Life is too short to be boring


Sunday, 03-Jun 14:26:21 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics