Back to Epicmafia

Lucid Read This

deletedover 10 years

You can't let Javascript on the website anymore. Hamhamed made a program that gives you karma and spams the Main Lobby chat wall, Foxie made one that assimilates your profile, and now Plexar has one that posts a link to pornhub in the lobby wall chat. You seriously can't let it on the website anymore.

~Bear

Javascript should be allowed on the website
14
Yes
4
No
deletedover 10 years
ok well tokens could be wasted by having their usernames changed by clicking java links and games could be refunded
over 10 years

DirtyHarry says

cookie hijacking, get rid of java


session cookies are secure, that's not really a threat
deletedover 10 years
cookie hijacking, get rid of java
over 10 years
Since my post was deleted here's the same thing I said before again:

The hearts are harmless, they just spread and can be removed. It's when some script kiddie comes along who all they can do is change the text from a heart to something stupid that ruins it.

And javascript is not the biggest threat. You have to voluntarily click links for it to do anything. This'll probably get deleted if I say what is, but I'm sure anyone with a clue knows anyway.
deletedover 10 years
over 10 years
lucid read this
deletedover 10 years
You wanna block javascript? On Epicmafia.com?
over 10 years
who cares honestly
over 10 years
People have been using scripts for years now. I don't believe blocking javascript is the answer but something should be done about this
over 10 years
Lucid is and didn't code basic script protection into the profile system. You can run arbitrary javascript on your profile which can do a lot of .
over 10 years
maybe not.
over 10 years
i believe so. there was some thing going around with heart symbols.
over 10 years
does it?? the only way that'd happen is with images and i thought that was fixed
over 10 years
it loads auto when you go on their profiles
deletedover 10 years
Does anyone ever READ what the link says before clicking on it? I didn't fall for that at all! Anyone...no one...okay I'll just slink away then....
deletedover 10 years
I mean javascript like the one on foxie's, hamhamed, and piexar's profile
over 10 years
there's not really a solution besides to prevent urls altogether, and that would be a bleak future
deletedover 10 years
Delete all messages from unknown users... dont even open thrm
over 10 years
That isn't Plexar btw, it's "Piexar".
deletedover 10 years
jus' saying.
over 10 years
stop clicking on suspicious links ^.^
deletedover 10 years
speeeeeed bump