7 ms·
My weekend project: anonymous, realtime message board with socket.io
This is just a simple node app on a small Joyent server!
- bromagosa 14y agoCool one! It'd probably be a good idea to crop titles and contents if they exceed a particular length.
- ecto 14y agoDoing this right now!
- zxcvb 14y agoI guess he's NOT GOING TO GET BANNED....
- ecto 14y agoPushed a limit of 200 chars
- zxcvb 14y agoMight want to stop same IP from posting over and over again...
- deleted 14y ago[deleted]
- ecto 14y agoI added a limit of 15 posts per minute for now
- galetoquantico 14y agoWhat if you try 1 post per 30 seconds ?
- brettbergeron 14y agoNice work dude! This is like 4chan, but real-time :D
- ecto 14y agoI'll take that as a compliment haha.
- voxx 14y agolol the xss possibilities on this thing are making me drool a bit and that guy is not going to get banned
- ecto 14y agoThis is just on a small Joyent server, running one process. I started it Friday night so there's still a few holes.
- sudonim 14y agoYeah, like it's not anonymous. Someone figured out that you can see all ip addresses (tied to comments) when you open up firebug.
- ecto 14y agoI fixed that actually. You can still get around my fix but I will fix the fix later.
- nsmartt 14y agoSo it's totally anonymous except you store the IP addresses, huh?
- ecto 14y agoCorrect.
- nsmartt 14y agoPretty misleading. The whole point of your experiment was to see how people would act if completely anonymous, right? They aren't. So your experiment is flawed.
- ecto 14y agoThey're anonymous in the context of the conversation. Anytime you visit a website, you know your IP is being logged.
- nsmartt 14y agoI can't reply to you so I'm replying to myself. I honestly thought you were going for full anonymity. In fact, my first thought was that you were taking it a step further than 4chan and that it would be interesting to watch.
- opendomain 14y agoDo NOT go to this service! It does not filter JavaScript and so is succeptble to XSS and other hacks. I sent on and clicked on a chat named 'Natalie portman' and it can up with an alert box that said 'no chance bro' and kept on popping up and I had to shut down my browser. Other than that - pretty kewl! Is the code open source?
- ecto 14y agoI actually got tricked by that too haha. I went into the database and deleted that, and pushed a fix to production.
- mkramlich 14y agoYou are now totally qualified to start a Bitcoin bank.
- nicoviarnes 14y agoI laughed a bit.
- deleted 14y ago[deleted]
- chrisbroadfoot 14y agoWho cares if it's open to XSS? Does the site have a cookie you care about? If it's truly anonymous, then it doesn't matter if someone forges your cookie.
- nsmartt 14y agoLet me start by saying that the notion that XSS can only be used to harvest cookies is a very common misconception. The truth is that, with XSS, any action a user may do on the vulnerable site (that doesn't require a password) can be mimicked. With an XSS vector in the board title (meaning the JavaScript would be injected into the page listing all boards) it would be possible to force all visitors to participate in a DDoS attack against this site. If I'm not mistaken, it would be possible to force the participation in a DDoS against ANY site. I'm fairly certain that cross-site ajax works fine in modern browsers, but without cookies to prevent abuse- cookies are not necessary for DDoS. Edit/Note: This does mean that any site could force visitors to participate in a DDoS attack. What prevents this from becoming common is the number of visitors required for a DDoS attack to succeed. This would probably not work on this site because the number of users is only ~6000. I don't know how many users would actually be required to dent a typical site. I do know that "Anonymous" recently used a client side DDoS tool on a large number of users. Edit 2: In light of http://news.ycombinator.com/item?id=4000301 http://news.ycombinator.com/item?id=4000301, I'll point out that XSS could result in the forced posting of illegal content, as well.
- DigitalSea 14y agoThis is actually a lot of fun man, kudos.
- ecto 14y agoThanks! I had a lot of fun writing it!
- DigitalSea 14y agoAre you planning on open sourcing the code via Github or something? I haven't built a Node app myself just yet, would be interesting to see how you did it.
- ecto 14y agoI think I might! The code is still kind of gnarly right now but I'll clean it up this week and decide then.
- biwuchen 14y agocool
- biwuchen 14y agonice
- joshryandavis 14y agoIt is a fun little site, I really enjoyed playing with it. You really need to add some spam prevention, title & comment length limits, fix exploits, etc. I wanted to play around with it some more, but it's just pure spam now.
- ecto 14y agoThanks! I really hate spammers :\
- ecto 14y agoI just added a basic spam detector and truncated title lengths :|
- ecto 14y agoAlso I had to upgrade my RAM pretty fast haha. Should be better now.
- deleted 14y ago[deleted]
- vics 14y agoNice MVP with critical mass reached.
- shousper 14y agoIt's like real-time reddit.. its be fun, but probably hard to make constructive, lol I like it, and envy the fact you could just create this on a whim over a weekend. I wish I had that kind of discipline when it comes to some of my spontaneous ideas!
- ma2xd 14y agoWhat kind of server do you use?
- ecto 14y agoThis is just a single process on a Joyent SmartMachine. It's the first time I've used them and I've been pleased!
- pcopley 14y agoSo you built 4chan without the user base.