Last modified: 2011-02-09 10:47:30 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T29261, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 27261 - Disable passing query strings through Special:Random
Disable passing query strings through Special:Random
Status: RESOLVED INVALID
Product: MediaWiki
Classification: Unclassified
Special pages (Other open bugs)
1.17.x
All All
: High major (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-02-08 18:25 UTC by Gavia immer
Modified: 2011-02-09 10:47 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Gavia immer 2011-02-08 18:25:22 UTC
1.17 has a new feature that allows tacking a query string onto the usual Special:Random syntax, resulting in loading an URL that combines the randomly-selected page name and the query string. This feature is not at all well thought-out; it can be used to construct an auto-vandalism URL to post anywhere you like on the Web, resulting in distributed mass-vandalism. Likewise a smart vandal can copy-and paste a handcrafted URL many times to vandalize many pages quickly. There are other bad things you can automate with this as well. I'm not going to post an example URL here, but any developer should feel free to mail me if you want one. Please disable this.
Comment 1 Sam Reed (reedy) 2011-02-09 10:40:26 UTC
See r65054
Comment 2 Bryan Tong Minh 2011-02-09 10:45:00 UTC
All actions that could lead to vandalism require an edittoken. There is no way that from outside the wiki you can directly edit a page or something like that.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links