I'm getting worried that they know something that we don't.
What does you mean, DX? If you don't mind my asking.
Do you have problems, concerns, or recommendations about the technical side of the Phoenix? Air them here. Compliments also welcome.
I'm getting worried that they know something that we don't.
What does you mean, DX? If you don't mind my asking.
Suela, our registration system is under attack by someone who appears to be trying to exploit some security hole there. As far as we know, no hole exists, but the attempts keep on coming. I'd have given up long ago, which is why I wondered if we're missing something. Besides that, it frelling annoying. Whoever it is is chewing up user names faster than a cancelled Minearverse show.
Would it be possible to obfuscate the registration page a little, such as replacing the text with numeric entities, or mixing things up a little for each page view?
I think all we really need to do to fight this particular script is just reject any user names or e-mail addresses that contain "@buffistas.org."
Would it be possible to obfuscate the registration page a little, such as replacing the text with numeric entities, or mixing things up a little for each page view?
Well, the attack is meant to hit e-mail form pages, which is one reason it's not working so well on the reg page. I don't think they mean to be registering. Obfuscation wouldn't be of further help.
Which also makes me wonder why they haven't gone after www.buffistas.org/email.php.
Maybe it is obfuscated? I have no idea. It's not the brightest attack.
reject any user names or e-mail addresses that contain "@buffistas.org."
So... they're trying to register as a Buffista with a Buffistas address? that... doesn't make a lot of sense.
Script kiddies never make sense -- it's not a person, probably, just a bot.
DX, the code should now block both usernames and registration addresses with buffistas.org in them.