Appreciate the responses.
If login is where the potential lies, then CAPTCHA would certainly take care of it.
lulzdev
Posts
-
Maximum password length: DOS Potential -
Maximum password length: DOS PotentialThat is not a bad idea. My concerns lie in the creation of an account where it has you make a password.
I barely know what I am talking about, buy in theory 1 very large string could cause some performance issues on the server end. Whether that be from encrypting, storing, or pulling the password.
I have seen 14 gig notepad documents with just strings of characters for Brute forcing, so I suppose the same could be used for initiating a Denial of Service.
-
Maximum password length: DOS PotentialAn excerpt from: http://www.tomsguide.com/us/django-long-password-security,news-17557.html
"A double-edged sword
In the case of a brute-force attack, the attacker is trying to gain access to the system. But the developer found that if the attackers are just trying to mess things up, they could go to Django's login page and repeatedly submit hundreds of extremely long "junk" passwords of thousands of characters or more.
Having to check all these junk passwords against the stored cryptographic hashes puts a heavy strain on Django's system and eventually overtaxes it.
The result is essentially a denial-of-service attack, which is when attackers bombard a server with website hits or other requests that, when combined, eventually bring the server offline.
There haven't been any known attacks that used this method. Nevertheless, Django has since patched this vulnerability by setting a limit on password length: 4096 bytes, or around 4,096 of the characters found on a keyboard. The updated version is available on Django's website. So what's the takeaway? Users should keep using long passwords. Developers, however, should be aware that strong password security could become a double-edged sword."
Going through the admin options and realized that there is not an option for a maximum password length.
I have seen, previously, this feature having its purpose questioned (https://github.com/NodeBB/NodeBB/issues/261), indicating it used to be a thing.. however it does not appear to be now. Does anybody know why?
-
Lost all my data ? Help pleaseI second this. A keyword based community Wiki would be a great idea. A process like configuring or securing redis is definitely something everyone should know, and being able to locate it, without work from other users is a good idea, that will educate many, and inconvenience few, as there will be there duplicate posts and questions.
-
Unread-count subcategory indicationsHello all,
Simple question; did not see it posted yet.
How can one incorporate an unread-count, indicating the count for a specific subcategory? For instance, the Announcements category, or a subcategory within.I have created a new navigation option, directing to a subcategory, but I would like to have an unread count appear on that option, but I need it to only show how many are unread in the specific section. I played around in the admin panel, to no avail, and any assistance would be greatly appreciated.
Thank you.
-
[slush-nodebb-plugin] NodeBB New Plugin Generator - Request for feedbackHmm, was it CSS in the custom section then?(rather than making template changes instead?) I remember someone talking about causing slowdowns in that custom section.
-
[slush-nodebb-plugin] NodeBB New Plugin Generator - Request for feedback@pitaj
It was my understanding that that was a method that reduces the speed of your site. A reduction in speed that could be mitigated by using plugins. -
[slush-nodebb-plugin] NodeBB New Plugin Generator - Request for feedbackmany javascripts would require a custom plugin to use with Nodebb, the more plugins you use the more expensive developing becomes. One that comes to mind offhand is the javascript meme generator. Just trying to understand the new hotness everyone is happy about.
-
[slush-nodebb-plugin] NodeBB New Plugin Generator - Request for feedbackAny chances of this new tool being able to wire up javascripts to work with nodebb?
Opening up easy access to javascripts directly as nodebb plugins, rather than secondary installs, would be a giant leap forward.
-
Wikipedialulz
-
WikipediaShitshow; insular community championing moded policies in a rhetorical style of self-defense that borders upon sad.
the first forum software written in node.js is not notable? I am guessing that node is the N-word mentioned.I gave them five bucks once...
-
Including jQuery mixin file in pluginMTGsalvation has this functionality, but with an older tech backend. It is very important to the UX of a mtg related site. Best of luck!
(I play Cheeri0s and Dredge in modern ) -
New projekt! Use NodeBB as base and skip Wordpess!which node_modules is custom-homepage supposed to be installed into? there is one in my account and one in the nodebb directory and the node_modules in the nodebb directory will not allow an install of anything, even with sudo.
-
Gamification@mparra said:
The agent in the CLAW example is also builded in node.js on a Raspberry Pi with an Arduino Mega connected, and they communicate with johnny-five library.
I am not sure that you could have said any more cool sounding things in a single sentence if you tried. Keep doing awesome stuff!
-
OpenCart: Cart and Store -
OpenCart: Cart and StoreThis is their integration forum. I've posted a thread requesting the NodeBB-OpenCaart interface, the thread has not as of yet been approved by mods. But, we could easily do the same, yes? We really do need a cart/store and integration opens up an entire constellation of functionalities.
-
Ok to update node.js to .12?super helpful community
-
Ok to update node.js to .12?npm rebuild on nodebb or nodejs?
-
Ok to update node.js to .12?Does .12 break nodebb?
-
[nodebb-plugin-videoplayer]if this replaced the inline youtube and other players it might reduce the bleeding of user data to these big data types