Author Topic: Journal "virus" spreading as we speak  (Read 2693 times)

MazelTovCocktail

  • **
  • Posts: 168
  • E-points: +5/-2
  • You smell somethin', Rabbit?
    • View Profile
Re: Journal "virus" spreading as we speak
« Reply #20 on: June 23, 2011, 08:50:57 am »
I don't understand why they don't take FA down for a few months or so to patch it all up. I mean I understand it being 'Neers cash cow or whatever, but one would think user security is more important than the greed?

Ugh.

I don't think Dragoneer has quite hit the stage of maturity at which the concept of "short term vs. long term" starts to make sense yet.
I don't like to hit little bitches with glasses, but when midgets step up, I stomp midget asses.

u63r

  • *
  • Posts: 33
  • E-points: +1/-7
    • View Profile
Re: Journal "virus" spreading as we speak
« Reply #21 on: June 24, 2011, 01:01:21 pm »
Neer has also taken care to make a front-page Fender post, complete with the rationale that deviantART is also coded by barely-literate PHP programmers in remote tribal regions of Kazhikstan.
I'm pretty sure they're based in California.

But seriously, for all dA's flaws, at least they actually try and fix their website problems in a timely manner.

Jim Demintia

  • Postcount ate Whippany, NJ
  • ****
  • Posts: 628
  • E-points: +24/-6
  • Deflator Mouse
    • View Profile
Re: Journal "virus" spreading as we speak
« Reply #22 on: June 28, 2011, 03:50:00 pm »
I expect this shit outta FA. Alkora wrote it as a computer-illiterate teenage graphic-design student and this will be the story of FA until it is either rewritten by someone with a clue or it goes offline. But dA is a little bit different, because in theory they are not stagnating like FA and are developing their site, improving it and what not. It's actually more of an embarrassment to them- theoretically they knew better.

Anyway, for some reason Dragoneer has updated the Fender post about this and the word salad is pretty awesome:

Quote from: Dragoneer
The script, an XRSF vulnerability, was the exact same issue which recently hit deviantArt. The script used an auto-generated form to post a journal user accounts. It was corrected.

Screen shot here for when he recovers from his post-AC hangover/liver failure and corrects the post. We know you read us, Sean Piche.

I'm pretty sure they're based in California.

I would not be surprised.
Can it be this sad design
Could be the very same
A wooly man without a face
And a beast without a name

pmart

  • *
  • Posts: 34
  • E-points: +2/-0
  • BAWWWWW
    • View Profile
XSS security holes, June '11 edition
« Reply #23 on: June 28, 2011, 08:27:21 pm »
Here we go again.  Not really worth starting a new topic over, but I can't wait to see what this is (and whether it's related to the June 21 submission exploit):

Quote
   
Administrator notice:

We are investigating an issue with uploading to the site right now. Please hold.

Conan

  • Sean Piche Wannabe Club
  • Postcount ate Whippany, NJ
  • ****
  • Posts: 603
  • E-points: +33/-9
  • ¯\(°_o)/¯
    • View Profile
Re: XSS security holes, June '11 edition
« Reply #24 on: June 29, 2011, 02:40:00 pm »
Here we go again.  Not really worth starting a new topic over, but I can't wait to see what this is (and whether it's related to the June 21 submission exploit):

Quote
   
Administrator notice:

We are investigating an issue with uploading to the site right now. Please hold.

MySQL crashed but it wasn't a crash!

Wonder if the crash has to do with last month's whitescreen "fix".