![]() |
|
|
#12 | |
|
Aug 2015
2×23 Posts |
Quote:
|
|
|
|
|
|
|
#13 | |
|
"/X\(‘-‘)/X\"
Jan 2013
22·733 Posts |
Quote:
\ [\cssId{happy}{\style{background-image:url(http://www.mersenne.org/manual_assignment/?cores=1&num_to_get=1&pref=101&exp_lo=&exp_hi=)}{x}}\] If I removed the space between \ and [ and the beginning of that, everyone who loads this post would start getting assignments. It's that easy. |
|
|
|
|
|
|
#14 |
|
If I May
"Chris Halsall"
Sep 2002
Barbados
260216 Posts |
Yup. And if someone malicious embedded something like this where a non-Primenet user visited, then an Anonymous assignment would be given which wouldn't expire for 180 days.
A bit of an Achilles' heel with Primenet. The good news is once noticed Aaron would be able to filter based on the referrer. |
|
|
|
|
|
#15 | |
|
"/X\(‘-‘)/X\"
Jan 2013
1011011101002 Posts |
Quote:
Not having [img] tags made this exercise a little more interesting. |
|
|
|
|
|
|
#16 | |
|
Undefined
"The unspeakable one"
Jun 2006
My evil lair
3×5×7×59 Posts |
Quote:
Does it require JS or something because on my machine it does nothing.
|
|
|
|
|
|
|
#17 | |
|
Serpentine Vermin Jar
Jul 2014
331110 Posts |
Quote:
Or that could just be me... I build servers with headroom for just such things. There's another mentality in the cloud computing world that you absolutely must run your systems at near 100%, you know, to get your money's worth or whatever. You don't want to pay for a system that's 80%+ idle. So for those folks, doing encryption on the front-end web server would be bad. The Primenet server should have the CPU headroom. It sometimes has periods of high activity on the DB side of things, but it's in good shape. Oh, and yes, the main reason is of course to encrypt password info... which could be done by POSTing that to https and calling it good, but then you don't get a happy lock icon in the address bar. A secondary reason is just that SSL is, for better or worse, how the web is going to work. We'll look back at the http 1.1 days when SSL was optional as being a quaint, archaic system. HTTP/2 with it's (de facto) compulsory security has a lot going for it, and the fact that security is required is simply the way it is. Google has said they look at security (or lack thereof) as a signal in weighting search relevance too. Primenet/GIMPS is not really dependent on search engines for traffic, although it helps when we get the extra attention and we get new people signing up. There probably will come a day when unsecured sites become the online ghettos. |
|
|
|
|
|
|
#18 | |
|
"/X\(‘-‘)/X\"
Jan 2013
1011011101002 Posts |
Quote:
It takes advantage of the MathTex JS library included on the forum. My guess is that it doesn't work with ancient versions of Firefox. |
|
|
|
|
|
|
#19 | |
|
Undefined
"The unspeakable one"
Jun 2006
My evil lair
3×5×7×59 Posts |
Okay, I didn't know. Fortunately I neutered it with "blahblah" just in case it did work.
Quote:
|
|
|
|
|
|
|
#20 |
|
Serpentine Vermin Jar
Jul 2014
7×11×43 Posts |
I've applied a redirect from http to https for this page:
http://www.mersenne.org/report_milestones/ Of course once you've hit the https version of the site, all links are relative and you'll stay https as you browse around. The one exception I came across that I need to make sure is NOT redirected is also related to a "canonical" rule I added (so mersenne.org is redirected to www.mersenne.org). It's for v4 clients that still hit a link that doesn't like to be tinkered with. Once I do fully implement a site-wide SSL redirect, that url would be left alone. Poor v4 clients. I should look again at how much activity that gets... it surprised me last time. Can't believe there are still so many out there.Anyway, the single page redirect was just to make sure it works. It does. |
|
|
|
|
|
#21 |
|
"/X\(‘-‘)/X\"
Jan 2013
22×733 Posts |
Once you're redirecting almost everything, don't forget to set the secure flag on the cookie.
|
|
|
|
![]() |
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Big milestone coming up | schickel | Aliquot Sequences | 8 | 2011-07-29 10:54 |
| Mersenne BOINC coming? | frmky | Software | 27 | 2011-02-20 08:52 |
| Dark times may be coming...? | OmbooHankvald | mersennewiki | 10 | 2005-10-24 06:26 |
| And the hits just keep on coming..... | R.D. Silverman | Factoring | 13 | 2005-10-04 10:02 |
| Coming to a DC project near you P4 2.4B/GA8SQ800 /pc3200 | dragongoddess | Hardware | 0 | 2003-03-22 15:49 |