republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Do you run a Movabletype blog? » The fix isn't very good
Uniqs:
36
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Thanks for the heads up! »

justin
Australian
join:1999-05-28
Brooklyn, NY

Host:
IPv6
Business Connectiv..
Home/Office setup ..
Console/Handheld g..
Console Tech

The fix isn't very good

Reading the fix that movabletype.org have done .. well, it doesn't strike me as particularly good. So now they've limited the script to one target address and a short message body?

A spam-bot with a list of N movable type domain names could, in parallel, spam N people per second, even if everyone fixed their script per the recommendation. Ok that isn't as efficient as spamming NxM people per second (the original script allowed lists of people). But it is still possible.

It would be better if movabletype.org put a challenge response token into the loop, so you can't POST to it unless you have done a GET of the form, first, and a delay as well. Better still, remove the ability to enter a custom message (where the advert goes) entirely!

Or just remove the script and do not allow anon users to send links to any email address they like.

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:

Re: The fix isn't very good

Me too, the fix is horrible. Basically, the fix shows that they are lazy and that they don't want to fix it the correct way.
--
WedgeAntilles250

nil
Java Geek
join:2000-11-27

Host:
Webmasters and Dev..
Forum Feature Requ..

Re: The fix isn't very good

In all fairness to Ben and Mena I don't think you can call them 'lazy' over a bad fix.. Movable Type is still a terrific tool and still free.. Hopefully they'll have a better fix soon, in the meantime, people should just remove the script altogether. There's no true need for it.
--
Life is too short to be boring
Forums » Do you run a Movabletype blog?Thanks for the heads up! »


Thursday, 10-Dec 08:04:06 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [119] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [68] AT&T Hints At Usage-Based iPhone Data Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Cross Server Dungeon Experience [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Forwarding previous owner's mail [Home Repair & Improvement]
· Icecrown 5-man strats [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Lawyers Claim Palin Hack Suspect's PC Had Spyware [Security]
· The aftermath [World of Warcraft]
· SB6120 Firmware update [Comcast HSI]
· Windows 7 boot manager editing questions [Microsoft Help]
· Adobe Flash Player version 10.0.42.34 [Security]