Strip or forbid Javascript in comments
-
A friend’s WP blog got slashdotted. Not fun at all: 10GB of traffic in 4 days, 95585 unique visitors. All of them kicking tyres and trying to be smart.
One of these clever sheep placed a javascript endless loop in his comment. The only way out is to kill your browser process, this exploit works under ie, firefox and opera, for windows. I could try the same here but it wouldn’t be polite.
How do I strip or disable javascript for comments. Specifically onmouseover events? I just replicated the exact problem in a comment on my 1.5.1.2 blog.
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
The topic ‘Strip or forbid Javascript in comments’ is closed to new replies.