Re: [MediaWiki-l] Security concern with {{FULLURL}} in edit of Portal pages

2012-09-25 Thread Brion Vibber
On Tue, Sep 25, 2012 at 11:28 AM, Tom Hutchison wrote: > Wondering if anyone else has run into this. Clicking on the edit link in a > portal styled page which uses the magic word, {{fullurl}} like this, > [{{fullurl:{{{editpage|/}}}|..**. Seems as if some are DNS'ing back to > this wiki and the

Re: [MediaWiki-l] Security concern with {{FULLURL}} in edit of Portal pages

2012-09-25 Thread Tom Hutchison
One more think here was my quick fix to plug the hole. From: [{{fullurl:{{{editpage|/}}}|... To: [http://www.domain.org{{localurl:{{{editpage|/}}}|... By changing to local, I could control the domain, but the question still is why does {{fullurl}} resolve back to parasites and sometimes the co

[MediaWiki-l] Security concern with {{FULLURL}} in edit of Portal pages

2012-09-25 Thread Tom Hutchison
Wondering if anyone else has run into this. Clicking on the edit link in a portal styled page which uses the magic word, {{fullurl}} like this, [{{fullurl:{{{editpage|/}}}|... Seems as if some are DNS'ing back to this wiki and the actual link when hovered over the word "edit" is resolving back

[MediaWiki-l] New extension: Diff

2012-09-25 Thread Jeroen De Dauw
Hey, I'm happy to announce the first release of a new little extension I wrote called Diff. https://www.mediawiki.org/wiki/Extension:Diff It's a small utility library which might be of use to anyone creating a new extension :) Cheers -- Jeroen De Dauw http://www.bn2vs.com Don't panic. Don't be