Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I also like others don't think that bashing competitors is the way to go for you, whether your product is great or not. The price listed at the end of the page adds to the bad taste for me.

However you may notice that your Demo page has been "hacked", in a truly great way, redirecting everyone to wordpress.org.

    <p style="text-align: justify;">This is a little test.&nbsp;<em> <strong>lol</strong></em></p>
    <p style="text-align: justify;">&nbsp;</p>
    <p>
        <script>// <![CDATA[
            window.location = 'http://wordpress.org';
        // ]]></script>
    </p>


Wow, I am at work and it just redirected me to pornhub... that is bad taste...


exactly... dammit...


The user input is not sanitised and since it's a demo it's open for everyone to edit.

I'd suggest maybe sanitising user input on the server end so that script tags don't get through.


It now has an infinite loop and I can't view it at all (oh snaps Chrome). I hate to criticise but OP - isn't this pretty irresponsible?


I guess it's a little too simple.


"Unlike Wordpress, we allow XSS..."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: