Hacker Newsnew | past | comments | ask | show | jobs | submit | mTano's commentslogin

Thank you very much for your comment. The top page has been modified to "wtf" characters for malicious users. Now that all the input forms and JavaScript have been removed, you can browse correctly.


Thank you very much for your comment. There was a part where the HTML of the top page was recursively repeated. We will consider how to improve it.


Thank you very much for your comment. We apologize for the inconvenience. I think that it does not support SSL and a warning is issued depending on the browser. When the funds to purchase https are accumulated, we will solve it with the highest priority.


You can have free SSL certification with Let's Encrypt! Highly recommended, good job on the site :)


Let's Encrypt was able to introduce free SSL authentication! Thank you for your advice!


Thank you very much for your comment. Can I get free SSL! We would like to thank you for your valuable information.


Thank you for your comment. The created site is "http://url-wiki.com". It's not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


Thank you for your comment. The created site is "http://url-wiki.com". It's not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


Thank you for your comment. The site I searched for was "http://url-wiki.com", not a note. I posted an article on how to use it in note, and I thought it would be easier to understand, but I'm sorry that it confused Hack News.


Thank you very much for your comment. We scrutinized the user's items and frozen users with porn related items. In the future, I would like to consider the reporting function and improve it so that it can be frozen efficiently.


Thank you very much for pointing out. I didn't realize there was a security hole. I would like to study a little more about the input form. For the top page, JavaScript has been completely removed.


You need to remove the vulnerable PHP script too


I would like to improve the security hole for PHP scripts as well. Thank you for giving us a very detailed point.


I'm sorry, it seems that the top page has been changed to wtf characters by a malicious user, so I will reissue it.


I think you need to take the site offline and go learn about sanitising inputs. Your site is fundamentally insecure at the moment.


Thank you very much for your comment. I felt that I hadn't studied enough about input forms and JavaScript. Learn about injection attacks.


I developed "http://url-wiki.com". note becomes the operation manual. I'm sorry I'm not used to using Hoker News.


I think it would have been much clearer to link straight to your site, as most of us don't know Japanese. However, url-wiki seems to be down at the moment, as all it says is "wtf". You may want to make a better error message.


I should have written a direct link. Sorry for confusing Hack News. After that, please be careful.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: