Stop means no. And no means no. So . . . stop.

Xander ,'Conversations with Dead People'


Buffistas Building a Better Board ++

Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.


DXMachina - Aug 31, 2005 3:20:56 am PDT #465 of 4671
You always do this. We get tipsy, and you take advantage of my love of the scientific method.

One thing we still need is a way to search for a user name by their e-mail address in the admins interface.


§ ita § - Aug 31, 2005 3:58:05 am PDT #466 of 4671
Well not canonically, no, but this is transformative fiction.

We still need a lot of things ... my biggest beef right now is the tag closing code. What we have now is better than nothing, but it frells up the HTML with abandon. Just in a less destructive way.

That's what I was going to parse out.

I know the larger font is a good idea, but I don't feel people fiending for it.

As for the searching for e-mail addresses -- it is important, but can be mitigated for th emoment by routing all those requests to me and I can poke through the database.

I'm thinking we should have an admin page, where all our sundry links are collected, so that left column doesn't get too long.

The other thing I'm jonesing on is cleaning up the CSS and removing much of the deprecated formatting in our HTML. DX, you can't really get your font stuff without that, and I know you want that muchly.


DXMachina - Aug 31, 2005 4:09:47 am PDT #467 of 4671
You always do this. We get tipsy, and you take advantage of my love of the scientific method.

As for the searching for e-mail addresses -- it is important, but can be mitigated for th emoment by routing all those requests to me and I can poke through the database.

Consider yourself routed. There's a request that I can't help in the admins inbox (along with a zillion fake user names). I tried searching the new users folder, but the request must be about a much older name.

The other thing I'm jonesing on is cleaning up the CSS and removing much of the deprecated formatting in our HTML. DX, you can't really get your font stuff without that, and I know you want that muchly.

In term of what's important for the site, though, I think the tag fixing thing would probably be of more use. Also, if you're working on code to block fake username requests, I think that should get priority, because we keep getting hit, and I'm getting worried that they know something that we don't.


§ ita § - Aug 31, 2005 4:20:40 am PDT #468 of 4671
Well not canonically, no, but this is transformative fiction.

I've cleaned the code so I'm sure we're not abusable, but it's still fucking annoying, and you're right -- kiddy needs to be headed off at the pass.

Maybe if I get some quiet time at work today.


Consuela - Aug 31, 2005 6:00:10 am PDT #469 of 4671
We are Buffistas. This isn't our first apocalypse. -- Pix

I'm getting worried that they know something that we don't.

What does you mean, DX? If you don't mind my asking.


DXMachina - Aug 31, 2005 6:18:11 am PDT #470 of 4671
You always do this. We get tipsy, and you take advantage of my love of the scientific method.

Suela, our registration system is under attack by someone who appears to be trying to exploit some security hole there. As far as we know, no hole exists, but the attempts keep on coming. I'd have given up long ago, which is why I wondered if we're missing something. Besides that, it frelling annoying. Whoever it is is chewing up user names faster than a cancelled Minearverse show.


Tom Scola - Aug 31, 2005 6:26:45 am PDT #471 of 4671
Mr. Scola’s wardrobe by Botany 500

Would it be possible to obfuscate the registration page a little, such as replacing the text with numeric entities, or mixing things up a little for each page view?


DXMachina - Aug 31, 2005 6:35:27 am PDT #472 of 4671
You always do this. We get tipsy, and you take advantage of my love of the scientific method.

I think all we really need to do to fight this particular script is just reject any user names or e-mail addresses that contain "@buffistas.org."


§ ita § - Aug 31, 2005 6:36:00 am PDT #473 of 4671
Well not canonically, no, but this is transformative fiction.

Would it be possible to obfuscate the registration page a little, such as replacing the text with numeric entities, or mixing things up a little for each page view?

Well, the attack is meant to hit e-mail form pages, which is one reason it's not working so well on the reg page. I don't think they mean to be registering. Obfuscation wouldn't be of further help.


DXMachina - Aug 31, 2005 6:37:38 am PDT #474 of 4671
You always do this. We get tipsy, and you take advantage of my love of the scientific method.

Which also makes me wonder why they haven't gone after www.buffistas.org/email.php.