Because who needs server side checks. It's 2017 and JS is all we need.https://twitter.com/MaximeEuziere/status/912981874372481026 …
-
-
Replying to @marcan42
You sure? If I just reenable the submit button with extra chars the post is sent and I get a 403.
1 reply 0 retweets 0 likes -
-
Replying to @marcan42
I did. Guess where the 403 comes from... Maybe the 280 char tweets use a different endpoint. Maybe it won't work if your language is Spanishpic.twitter.com/Me0jIBTVkV
1 reply 0 retweets 0 likes -
Replying to @klon
Have you actually tried the linked userscript? I assume enabling cramming changes the POST data in some other way.
1 reply 0 retweets 0 likes -
Replying to @marcan42
If it does, then it turns out that there is this tiny bit more than JS validation as you said.
1 reply 0 retweets 0 likes -
Replying to @klon
Point is there's no server side validation for who is supposed to have the feature available.
1 reply 0 retweets 0 likes -
Replying to @marcan42
Point is, it still requires some technical knowledge most of the people don't have to (ab)use so it really doesn't matter...
1 reply 0 retweets 0 likes
Mental note: you're banned from security work for anyone I work with :p
-
-
Replying to @marcan42
Mental note: you're banned from work involving risk or impact calculations for anyone I work with :p
1 reply 0 retweets 1 like -
Replying to @klon
Let me know what your mitigation is for all the tweets with >140 CJK chars being posted in violation of intended policy :p
1 reply 0 retweets 0 likes - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.