If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: blog.bawolff.net - Bawolff's rants.

site address: blog.bawolff.net redirected to: blog.bawolff.net

site title: Bawolff's rants

Our opinion (on Wednesday 05 August 2026 8:10:03 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


Hashtags existing on this website:




Meta tags:

Headings (most frequently used words):

2025, conclusion, the, we, do, it, how, data, on, about, october, can, pure, css, viewer, calculator, vulns, in, 30, structured, commons, thursday, january, new, what, year, this, bawolff, rants, followers, blog, archive, me, tuesday, march, 31, 2026, sunday, better, enter, saturday, wednesday, july, everyone, favourite, security, technology, csp, go, simpler, does, work, many, will, stop, try, yourself, friday, february, 28, 16, giving, wikiapiary, kick, web, server, concurrency, request, limits, database, 360, panorama, did, xssprotector, high, moderate, low, preventing, xss, mediawiki, extension, to, protect, your, wiki, exactly, are, doing, exploring, model, happy, belated, signpost, article, so, all, blank, nodes, for, creator, functionally, dependent, predicates, querying, system,

Text of the page (most frequently used words):
the (408), and (124), that (122), this (100), for (97), can (70), you (65), but (65), with (62), not (61), #mediawiki (55), are (54), was (45), have (39), like (39), some (38), its (36), req (36), use (33), security (33), 2025 (32), they (32), all (31), query (31), make (30), there (30), would (30), set (30), want (28), time (27), should (27), page (27), what (25), about (25), more (24), think (24), only (23), very (23), cve (23), also (22), really (22), things (22), xss (22), which (20), just (20), has (20), don (20), work (20), been (20), from (20), http (20), wikimedia (19), out (19), seems (19), them (19), extension (19), wiki (18), user (18), try (18), people (18), much (18), instead (18), data (18), users (17), get (17), commons (17), system (17), csp (17), css (16), other (16), where (16), most (16), slow (16), image (16), requests (16), one (15), thing (15), however (15), even (15), same (15), any (15), new (14), queries (14), return (14), project (13), using (13), backend (13), special (13), beresp (13), see (12), something (12), their (12), script (12), being (12), here (12), will (12), still (12), service (12), url (12), take (12), wikipedia (11), bawolff (11), could (11), used (11), how (11), different (11), bit (11), sort (11), many (11), php (11), property (11), vulnerabilities (11), load (11), such (10), goal (10), example (10), after (10), way (10), year (10), did (10), into (10), doing (10), low (10), since (10), when (10), blank (10), first (10), because (10), sure (10), javascript (10), cube (10), faces (10), request (10), article (9), wikidata (9), lot (9), least (9), makes (9), already (9), now (9), down (9), actually (9), site (9), distinct (9), then (9), schema (9), part (9), these (9), were (9), view (9), server (9), labels (8), calculator (8), know (8), number (8), based (8), cool (8), open (8), why (8), maybe (8), before (8), than (8), less (8), doesn (8), seemed (8), often (8), find (8), who (8), almost (8), nodes (8), though (8), case (8), too (8), group (8), important (8), look (8), support (8), requires (8), lets (8), template (8), wikiapiary (8), accept (8), encoding (8), posts (7), comments (7), posted (7), add (7), might (7), back (7), ideas (7), right (7), while (7), once (7), going (7), optimization (7), blazegraph (7), method (7), seem (7), creator (7), uses (7), metadata (7), weird (7), properties (7), structured (7), idea (7), does (7), pages (7), those (7), normal (7), called (7), api (7), better (7), october (7), chrome (7), face (7), purge (7), https (6), templates (6), january (6), wmf (6), little (6), conclusion (6), side (6), smw (6), kind (6), good (6), help (6), core (6), isn (6), anything (6), web (6), two (6), reason (6), writing (6), post (6), few (6), had (6), february (6), result (6), limit (6), means (6), images (6), aren (6), exactly (6), over (6), results (6), simple (6), your (6), database (6), file (6), value (6), team (6), super (6), severity (6), code (6), extensions (6), tags (6), resources (6), common (6), thus (6), link (6), cache (6), status (6), full (6), zoom (6), separate (6), transform (6), transforms (6), translate3d (6), foo (6), signpost (5), without (5), model (5), write (5), wrote (5), source (5), quite (5), explore (5), rdf (5), traditional (5), far (5), month (5), big (5), views (5), matter (5), blog (5), pretty (5), sparql (5), unfortunately (5), end (5), terms (5), non (5), either (5), sometimes (5), impossible (5), able (5), added (5), media (5), type (5), point (5), happen (5), talk (5), otherwise (5), never (5), vulns (5), enabled (5), pass (5), attributes (5), xssprotector (5), messages (5), needed (5), escape (5), max (5), viewer (5), pure (5), var (5), rotatex (5), true (5), bots (5), semanticmediawiki (5), bar (5), default (5), index (5), ram (5), 127 (5), varnish (5), backend_hint (5), logged (5), elsif (5), deliver (5), allowed (4), own (4), update (4), essentially (4), issue (4), programming (4), outside (4), computer (4), unique (4), querying (4), love (4), always (4), interesting (4), keep (4), feel (4), both (4), perhaps (4), done (4), taking (4), class (4), mostly (4), got (4), real (4), guess (4), last (4), nonetheless (4), past (4), check (4), filter (4), subquery (4), put (4), order (4), best (4), files (4), whole (4), running (4), sense (4), each (4), making (4), main (4), between (4), missing (4), hash (4), especially (4), bot (4), responsible (4), change (4), node (4), username (4), solution (4), allow (4), parts (4), hard (4), various (4), access (4), show (4), designed (4), linked (4), browser (4), text (4), style (4), recently (4), bypass (4), cases (4), multiple (4), note (4), come (4), admin (4), stop (4), probably (4), works (4), need (4), loading (4), attacks (4), attribute (4), regex (4), disable (4), major (4), content (4), evil (4), html (4), else (4), tried (4), perspective (4), allows (4), complex (4), left (4), apply (4), july (4), performance (4), config (4), control (4), basically (4), external (4), tool (4), animation (4), click (4), 360 (4), equirectangular (4), cubemap (4), large (4), panorama (4), 180deg (4), pannellum (4), matches (4), disk (4), memory (4), cpu (4), host (4), port (4), 8088 (4), max_connections (4), wait_limit (4), wait_timeout (4), sub (4), forwarded (4), uncacheable (4), march (4), december (4), org (3), problems (3), wait (3), height (3), made (3), read (3), series (3), recent (3), goals (3), next (3), creative (3), involved (3), sphere (3), land (3), ecosystem (3), wrong (3), under (3), stuff (3), haven (3), learning (3), clear (3), local (3), great (3), branch (3), off (3), amount (3), relative (3), 2023 (3), didn (3), suddenly (3), around (3), implementation (3), via (3), wikibase (3), hack (3), general (3), beginning (3), values (3), graph (3), counting (3), created (3), creators (3), numbers (3), thought (3), predicate (3), random (3), extract (3), term (3), functions (3), count (3), rest (3), interested (3), named (3), putting (3), trick (3), remote (3), sdc (3), sha1 (3), well (3), inserting (3), opinion (3), size (3), wdt (3), specify (3), ideally (3), theory (3), prevent (3), nobody (3), minute (3), average (3), auth (3), servers (3), client (3), significant (3), log (3), tends (3), through (3), version (3), high (3), tested (3), blocked (3), single (3), none (3), close (3), may (3), following (3), conventions (3), course (3), message (3), become (3), attacker (3), display (3), templatestyles (3), restrict (3), form (3), tag (3), src (3), needs (3), meta (3), base (3), target (3), match (3), processing (3), changes (3), privacy (3), piece (3), anyone (3), connection (3), world (3), viable (3), effort (3), send (3), address (3), potential (3), previous (3), easy (3), difficult (3), policy (3), nothing (3), bunch (3), edit (3), setup (3), wikis (3), token (3), discussiontools (3), rate (3), checkuser (3), fix (3), button (3), mode (3), likely (3), ago (3), approach (3), scene (3), viewpoint (3), yaw (3), pitch (3), software (3), embedded (3), effect (3), give (3), credit (3), together (3), projection (3), rotatey (3), fallback (3), directly (3), turn (3), timeout (3), mysql (3), optimize (3), indexes (3), looked (3), semantic (3), mariadb (3), first_byte_timeout (3), 200s (3), between_bytes_timeout (3), synth (3), agent (3), msie (3), browse (3), everything (3), threads (3), swap (3), kick (3), august (3), september (3), november (3), april (3), june (3), rants (3), older (2), details (2), later (2), provide (2), interactive (2), solve (2), having (2), spreadsheet (2), define (2), cells (2), readers (2), med (2), mdwiki (2), internal (2), worked (2), thursday (2), life (2), along (2), sucked (2), third (2), party (2), long (2), space (2), found (2), databases (2), gotten (2), start (2), discussion (2), contributions (2), possibilities (2), fail (2), working (2), maintenance (2), volunteer (2), towards (2), level (2), apps (2), learn (2), fun (2), current (2), rare (2), community (2), join (2), trying (2), technical (2), practice (2), said (2), ctf (2), writeups (2), mudcon (2), terrible (2), 2022 (2), happy (2), talking (2), his (2), reasonable (2), wanted (2), petered (2), myself (2), years (2), anyways (2), yaron (2), filtering (2), hacky (2), uri (2), death (2), arbitrary (2), table (2), initially (2), top (2), magnitude (2), p170 (2), vast (2), majority (2), helpful (2), enough (2), suggest (2), fast (2), list (2), fetch (2), information (2), item (2), optimizer (2), cannot (2), minimize (2), cross (2), dataset (2), label (2), usually (2), missed (2), description (2), string (2), format (2), automatically (2), width (2), duplicating (2), hand (2), p1163 (2), question (2), fact (2), similarly (2), predicates (2), functionally (2), p4174 (2), relationship (2), supposed (2), above (2), happening (2), largely (2), sysadmin (2), normally (2), another (2), breaks (2), moving (2), heard (2), process (2), eventually (2), scrape (2), understand (2), fully (2), per (2), spikes (2), reqs (2), usage (2), logging (2), hindrance (2), official (2), instructions (2), dev (2), certain (2), cookies (2), described (2), behind (2), biggest (2), temporary (2), edges (2), helping (2), exploring (2), walkabout (2), infosec (2), please (2), master (2), curious (2), causes (2), release (2), including (2), stopped (2), issues (2), say (2), informational (2), hasn (2), won (2), coding (2), problematic (2), widgets (2), initial (2), hooks (2), resource (2), scriptless (2), attempt (2), block (2), risk (2), decided (2), care (2), action (2), reduce (2), forms (2), links (2), uris (2), additional (2), disables (2), unsafe (2), inline (2), dynamic (2), during (2), scripts (2), honestly (2), outputpage (2), processes (2), definitely (2), possible (2), body (2), i18n (2), generally (2), contain (2), miraheze (2), interface (2), anymore (2), useful (2), easily (2), somewhat (2), retrospect (2), dedicated (2), deployed (2), effective (2), tackle (2), technology (2), problem (2), bring (2), everyone (2), deal (2), advice (2), serious (2), install (2), properly (2), parse (2), consider (2), thanks (2), exclude (2), officially (2), unsupported (2), configuration (2), private (2), affected (2), oathauth (2), 2fa (2), showing (2), variable (2), recentchanges (2), bug (2), copy (2), moderate (2), interaction (2), fairly (2), sanitize (2), stored (2), parser (2), adding (2), higher (2), resolution (2), zoomed (2), speed (2), pinch (2), gestures (2), limitations (2), upload (2), parameterized (2), starting (2), every (2), buttons (2), previously (2), variables (2), implement (2), lua (2), wikitext (2), element (2), yet (2), github (2), imagine (2), glue (2), lauri (2), veerde (2), representation (2), rotatez (2), 270deg (2), 90deg (2), focal (2), rad (2), ignore (2), webgl (2), shown (2), rectangle (2), proper (2), extra (2), plane (2), entire (2), immersive (2), parserfunctions (2), seconds (2), multivalued (2), array (2), elasticsearch (2), helped (2), room (2), saw (2), small (2), effectively (2), limited (2), piling (2), away (2), gracefully (2), excimer (2), happens (2), traffic (2), old (2), 300s (2), localhost (2), acl (2), vcl_recv (2), serve (2), grace (2), comes (2), crawling (2), 403 (2), authorization (2), cookie (2), offset (2), 136 (2), opera (2), applebot (2), blocking (2), unset (2), gzip (2), deflate (2), ttl (2), public (2), outright (2), scrapper (2), backends (2), worse (2), overloaded (2), installed (2), giving (2), 2026 (2), subscribe, atom, home, gadgets, let, wikipedia_signpost, technology_report, manipulating, interactivity, opened, surprising, opportunities, diagrams, demonstrations, programmable, developers, settled, esque, formula, hired, medical, calculators, calculate, bmi, reader, enters, weight, newspaper, contributed, published, comfort, zone, pursue, hobbies, contribs, prototyping, avoid, fixing, allegedly, paid, staff, intentional, planning, yearly, felt, reporting, cargo, trade, offs, direction, wikiproject, funded, spurned, influence, whether, bad, stagnant, late, 2000s, incrementally, improved, upon, sign, maturing, crazy, improving, critical, appreciated, ever, direct, rust, spend, concepts, algorithms, university, brush, relevant, creativity, traditionally, paint, pictures, beginner, acrylic, painting, center, interests, silly, game, forgotten, shorter, cuff, blogger, analytics, unclear, tremendous, suppose, hope, others, nice, short, looking, realize, increase, throughout, inspired, tyler, cipriani, maintain, belated, poking, commonswalkabout, issomevalue, arranges, 000, 7200, range, trust, blaze, consistently, returning, required, grouped, cause, morbid, fascinating, sampling, interpolating, gives, within, complicated, million, items, millions, considered, involving, runs, subset, broad, trends, sample, involves, mean, basic, pattern, services, grouping, aggregate, aggregrate, function, basis, critically, aggregation, applicable, fetching, counts, ensuring, copious, subqueries, due, isolated, communication, communicating, tricky, spread, clauses, unless, title, manipulation, bizarre, omission, canonical, broken, internally, xmp, included, namespace, adds, contentsize, encodingformat, numberofpages, equivalent, aka, mime, surely, manually, filling, poor, design, p2048, p2049, p4092, checksum, p3575, depend, controlled, edited, dependent, feels, ontologically, resort, undoubtedly, fine, rectified, modifying, chain, placeholders, equal, says, playing, regardless, suspect, cut, funding, leaves, concert, broadly, scared, position, solely, remit, blame, forward, theories, sell, enterprise, banner, companies, company, convincing, enshitification, larger, interest, broader, instance, trivial, compared, clearly, averaging, occasional, min, comparison, 7500, graphs, federation, act, front, theoretically, friendly, necessarily, professional, programmers, console, steps, authentication, shut, criticism, situation, sounded, restriction, appears, permanent, t376979, t297995, xkcd, controversial, feeling, abandoned, rough, successful, tools, authoring, interacting, maintaining, lacking, ought, importantly, dual, organization, free, category, newer, committed, app, showed, photographed, benno, rothenberg, arabah, desert, 1952, addicting, quality, donated, museums, bodies, water, located, place, ireland, fields, friday, rel1_xx, rel1_39, compatible, download, unusual, behaviour, test, protections, yourself, ones, explicitly, believe, remaining, additionally, counted, phab, ticket, reported, debatable, triaging, vulnerability, disagree, medium, unauthenticated, although, par, vuln, rights, exploit, exhaustively, ymmv, fixed, intrinsically, mere, came, greatest, brag, bypasses, break, testing, turns, misses, attackers, potentially, unclosed, markup, contains, selectors, relatively, targets, self, tricks, sketchy, confidence, elem, legacy, primary, ditto, equiv, refresh, redirect, adjust, loaded, directive, output, replace, resourceloader, addheaditem, harm, replacing, entity, onclick, onfocus, sanitization, ignores, innerhtml, attr, recommended, entirely, insight, occur, except, golden, involve, starters, focus, cared, doubt, installs, closer, dealing, political, wrangling, absolute, minimal, product, simpler, sites, admins, customize, sounds, soft, norms, expected, implicitly, someone, permission, enforce, scope, job, died, foundation, 2020, tasked, finished, developed, further, sads, wisdom, afterwards, operative, word, options, knobs, looks, foremost, grab, bag, solutions, conversation, favourite, shouldn, engage, promiscuous, browsing, quarter, century, y2k, typical, attack, specific, accounts, obviously, environment, secret, scripting, preventing, protect, wednesday, overall, emphasize, triggered, configurations, dos, spent, hardening, prevented, worried, vector, t398636, 61657, insert, sticky, header, visualeditor, t395858, 61655, sensitive, t397497, 61654, deleted, entries, considering, configuring, tell, textextracts, t397577, 61653, authorizeread, extracts, endpoint, t396951, freeotp, refuses, t401862, t402094, 11173, reauth, enabling, bypassed, submitting, t364910, t396248, 11175, supported, configs, t397580, 61652, permissions, pageinfo, confirmedit, t355073, 61635, apifancycaptchareload, reuse, badcaptcha, t402077, 61648, t404805, 61658, globalcontributions, t403408, 61651, tempuser, expired, tooltip, t403761, 61645, codextablepager, t402313, 61642, submit, codex, htmlforms, t298690, 61641, maxsize, queryallpages, miser, t402075, 61640, t398706, 61646, leaking, hidden, usernames, watchlist, t403757, 61643, suppressed, rcfeeds, t280413, 61639, manuallogentry, getdeleted, getrecentchange, t394856, 61637, three, live, preview, t394396, 61636, rawelement, t387478, 61634, age, redirects, visual, editor, account, ultimately, 61656, unwrapped, t397232, aside, amazing, gui, ying233, 61638, t401099, ratings, rating, yesterday, bundled, fared, released, compromise, changing, safety, against, months, frustrated, lack, defensive, anti, measures, hence, born, saturday, improvement, quo, testament, modern, smidge, future, investigate, annotations, hotspots, limitation, detail, zooms, tile, chose, affects, blurry, screen, virtual, reality, device, orientation, holds, phone, panoviewer, usecases, notably, annoying, bright, usable, albeit, framed, pleasing, composition, independently, objected, success, mcdonnell, douglas, phantom, drag, mouse, finger, dragging, alive, sudden, jumps, clicking, play, stylesheet, option, transitions, rotation, move, ahead, adjusts, displayed, plug, formulas, gadget, pseudo, checkboxes, clickable, mind, scroll, clicked, controls, starts, ugly, pain, changed, styles, calc, secure, holding, breath, proposal, stylesheets, notable, enter, messes, video, gnarly, cubemap_player, doc, animations, rotating, translated, persnickety, firefox, tearing, artifacts, smoother, confusing, overlapping, transformed, disappear, reappear, thank, stack, overflow, explaining, converted, translations, rotations, viewing, angle, appropriate, website, conversion, tim, starling, cli, fruition, pano, projector, jaxry, labelled, arieee, arts, craft, print, scissors, inside, shifted, notice, represented, convert, spherical, supports, affine, transformations, fallbackimgsize, math, tan, hfov, canvas, clientwidth, translatez, object, keys, queryselector, pnlm, continue, partial, webkittransform, com, mpetroff, blob, libpannellum, l835, l856, inspiration, browsers, review, getting, kafkaesque, hell, alternative, thedj, happened, 2019, wrapper, library, pannoviewer, distortions, projected, flatten, distorting, globe, shape, continents, earth, distorted, artistically, illustrating, topic, rendering, cooler, fighter, cockpit, couple, photos, desired, typically, panoramas, picture, surrounding, camera, displaying, experience, truly, photospheres, sunday, competing, catalogue, impact, originally, speedy, outliers, takes, 600, hitting, greater, faster, apparently, multi, valued, returned, row, sql, inner, condition, beside, wouldn, separately, oversight, 5000, answers, sortkey, indexed, latency, providing, array_map, functionality, served, innodb, search, optional, module, dependency, searches, intersection, operators, path, removing, smw_hash, bytes, buffer, pool, compressing, revisions, tables, dropped, 160gb, questionable, glance, select, harder, reasons, filed, noticed, vanilla, defined, bumped, max_heap_table_size, tmp_table_size, tmp_memory_table_size, 800mb, obvious, 128, settings, determines, 23gb, 128mb, wonder, subtract, upped, 11gb, increased, orders, instantly, innodb_buffer_pool_size, iotop, excessive, 200, killed, ensures, run, careful, global, max_statement_time, package, 300, itself, unlike, execution_time, handling, applies, wall, clock, overload, split, amongst, passed, wgrequesttimelimit, answered, wasting, cascade, throughput, falls, slowed, business, jam, trigger, frankly, questionably, optimized, lots, longer, stayed, pointless, gone, limits, connections, queue, 10s, 30s, 60s, 120s, whenever, received, objects, minutes, expiry, respond, 500s, anywhere, 405, externalagent, detect, session, name, cached, ession, cacheable, itle, samsung, limiting, behaved, 012, createaccount, userlogin, normalize, vary, vcl_pipe, necessary, rewriting, vcl_hit, obj, document, successfully, retrieved, vcl_backend_response, 50x, responses, 500, 502, 503, 504, ended, facebook, aggressive, hate, lurkers, contributors, paging, expensive, render, everywhere, spider, features, ability, classes, four, diffs, history, ends, false, positives, metric, comparatively, given, gave, static, cheap, maximum, flight, reducing, significantly, deduplicating, extent, twice, setting, apache, 150, spike, fight, becomes, causing, pile, slowing, halt, mention, failure, accomplish, assumed, partially, contributing, factor, paying, attention, hosting, bane, existence, concurrency, extremely, flakey, timing, reminded, existed, tracked, isntances, james, hare, track, briefly, mentioned, forever, allowing, annotating, represents, relationshops, semanitc, days, listening, talks, conference, aimed, tuesday, complete, profile, 2009, 2010, 2011, 2012, 2013, 2021, 2024, archive, followers, collection, opinions, whatever,


Text of the page (random words):
h your mouse or finger unfortunately more complex gestures like pinch zoom aren t viable but dragging to change viewpoint really makes it come alive you can see the results at the mcdonnell douglas f 4 phantom ii article conclusion so far i ve put the new template on a few pages thus far nobody has objected so success there are still a few limitations most notably it requires users to upload the cube faces as separate images which is a bit annoying on the bright side though the different faces are usually usable images albeit perhaps not framed in the most pleasing composition so there is potential that they might be used independently the biggest reason why this is an issue is it means only people who know how to extract the faces can use the template we can t do full screen or virtual reality mode where the viewer users the device orientation api to show the scene based on how the user holds their phone nonetheless we can still link to the external panoviewer tool for those usecases similarly pinch to zoom gestures do not work another major limitation is we can t do dynamic level of detail loading ideally if the user zooms in we should load a higher resolution tile of the part they are zoomed in at that is not viable with the current approach instead we have to chose a resolution from the get go and load only that too high and it affects page load speed too low and the image is blurry when zoomed in the future it might be interesting to investigate adding support for annotations or linked hotspots on the whole though i think its a big improvement over the status quo and a testament to what is possible with modern css and a smidge of javascript posted by bawolff at 8 02 am no comments labels media templates wiki saturday october 4 2025 how did xssprotector do a few months ago frustrated by the lack of defensive anti xss measures in mediawiki i decided to make my own hence was born extension xssprotector this extension is a compromise its the best i can do from an extension without changing anything in mediawiki however i think it does provide real safety against the most likely vulnerabilities in mediawiki yesterday mediawiki released a security update for core and bundled extensions so lets see how xssprotector fared note severity ratings for vulns are my own opinion as there is no official rating the vulns high t401099 cve 2025 61638 security sanitize data attributes stored xss in mediawiki s parser as an aside this is an amazing find by gui ying233 its not often that people find stored xss in mediawiki s core parser moderate t397232 cve 2025 61656 security sanitize attributes unwrapped from data ve attributes basically if you can trick a user to copy and past something evil into visual editor you can take over their account moderate because it requires complex user interaction but is ultimately fairly serious low t387478 cve 2025 61634 security rest set cache control value of max age 60 for redirects t394396 cve 2025 61636 security escape rawelement content t394856 cve 2025 61637 security escape three system messages used by live preview t280413 cve 2025 61639 security use manuallogentry getdeleted in getrecentchange not an xss type bug t403757 cve 2025 61643 security don t send suppressed recent changes to rcfeeds t398706 cve 2025 61646 security prevent leaking hidden usernames in watchlist recentchanges t402075 cve 2025 61640 security parse messages instead of inserting them as html t298690 cve 2025 61641 security api disable maxsize in queryallpages in miser mode t402313 cve 2025 61642 security escape submit button label for codex based htmlforms t403761 cve 2025 61645 security fix i18n xss in codextablepager checkuser t403408 cve 2025 61651 security fix xss in tempuser expired link tooltip message checkuser t404805 cve 2025 61658 security add config variable to exclude from globalcontributions checkuser t402077 cve 2025 61648 security escape system messages before inserting them as html confirmedit t355073 cve 2025 61635 security apifancycaptchareload reuse badcaptcha rate limit discussiontools t397580 cve 2025 61652 security in api check user read permissions before showing pageinfo i consider this low as it requires an unsupported configuration people who have private wikis using officially supported configs are not affected discussiontools t364910 t396248 cve 2025 11175 security discussiontools should use better regex oathauth t401862 t402094 cve 2025 11173 security reauth for enabling 2fa can be bypassed by submitting a form oathauth t396951 freeotp refuses to add mediawiki s 2fa details because token is unsafe textextracts t397577 cve 2025 61653 security add authorizeread check for extracts endpoint i m considering this low because it requires configuring mediawiki in an officially unsupported configuration normal private wikis are not affected as far as i can tell thanks t397497 cve 2025 61654 security exclude deleted entries when counting thanks i think most users don t really consider this sensitive information visualeditor t395858 cve 2025 61655 security properly escape and parse system messages vector t398636 cve 2025 61657 security insert sticky header labels as text instead of html in conclusion it stopped all the xss vulns including the two that actually matter for your average mediawiki setup overall it got 11 out of 24 or 46 however i think its important to emphasize that most of the low vulnerabilities either can only be triggered by an admin can only happen in rare configurations or are dos vulnerabilities that only matter if you ve already spent significant effort doing performance hardening xssprotector prevented all the vulnerabilities that your average mediawiki install should be worried about posted by bawolff at 10 56 am no comments labels infosec mediawiki wiki wednesday july 30 2025 preventing xss in mediawiki a new extension to protect your wiki its no secret that the vast majority of serious security vulnerabilities in mediawiki are cross site scripting xss xss is where an attacker can put evil javascript where they aren t supposed to in order to take over other users for example the typical attack would look like the attacker putting some javascript in a wiki page the javascript would contain some instructions for the web browser like make a specific edit then anyone who views the page would make the edit essentially it lets evil people take over other users accounts this is obviously quite problematic in a wiki environment this is the year 2025 we shouldn t have to deal with this anymore back in y2k the advice was that web users should not engage in promiscuous browsing a quarter of a century later we have a better solution content security policy everyone s favourite security technology csp content security policy csp is a major web browser security technology designed to tackle this problem its actually a grab bag of a lot of things which sometimes makes it difficult to talk about as its not one solution but a bunch of potential solutions to a bunch of different problems thus when people bring it up in conversation they can often talk past each other if they are talking about different parts of csp first and foremost though csp is designed to tackle xss the traditional wisdom with csp is that its easy if you start with it but difficult to apply it afterwards in an effective way effective being the operative word since csp has so many options and knobs it is very easy to apply a csp policy that does nothing but looks like it s doing something this isn t the first time i ve tried mediawiki and csp back when i used to work for the wikimedia foundation in 2020 i was tasked with trying to make something work with csp unfortunately it never really got finished after i left nobody developed it further and it was never deployed sads part of the reason is i think the effort tried to do much all at once from wikimedia s perspective there are two big issues that they might want to solve xss and privacy xss is very traditional but privacy is somewhat unique to wikimedia wikimedia sites allows users and admins to customize javascript this is about as terrible an idea as it sounds but here we are there are various soft norms around what people can do generally its expected that you are not allowed to send any data even implicitly such as someone s ip address by loading an off site resource without their permission csp has the potential to enforce this but its a more complex project then just the xss piece in theory the previous attempt was going to try and address both which in retrospect was probably too much scope all at once relative to the resources dedicated to the project in any case after i left my job the project died can we go simpler recently i ve been kind of curious about the idea of csp but simple what is the absolute minimal viable product for csp in mediawiki for starters this is just going to focus on xss outside of wikimedia the privacy piece is not cared about very much i don t know maybe miraheze care not sure but i doubt anyone else does most mediawiki installs there is a much closer connection between the interface admin group and the people running the servers thus there is less need to restrict what interface admin group can do in any case i don t work for wmf anymore i m not interested in dealing with all the political wrangling that would be needed to make something happen in the wikimedia world however wikimedia is not the only user of mediawiki and perhaps there is still something useful we could easily do here the main insight is that the body of article and i18n messages generally should not contain javascript at all but that is where most xss attacks will occur so if we can use csp to disable all forms of javascript except script tags and then use a post processing filter to filter all script tags out of the body of the article we should be golden at the same time this should involve almost no changes to mediawiki this is definitely not the recommended way of using csp its entirely possible i m missing something here and there is a way to bypass it that said i think this will work what exactly are we doing so i made an extension xssprotector here is what it does set csp script src attr none this disables html attributes like onclick or onfocus code following mediawiki conventions should never use these but they are very common in attacks where you can bypass attribute sanitization it is also very common in javascript based attacks since the innerhtml js api ignores script tags but processes the on attributes look for script tag in content added for output i e in outputpage and replace it with script tag mediawiki code following coding conventions should always use resourceloader or at least outputpage addheaditem to add scripts so only evil stuff should match if it is in an attribute there should be no harm with replacing with entity ditto for meta and base tags kind of a side point but you can use meta http equiv refresh to redirect the page base can be used to adjust where resources are loaded from and sometimes to pass data via the target attribute we also use base uri csp directive to restrict this add an additional csp tag after page load script src elem this disables unsafe inline after page load mediawiki uses dynamic inline script tags during initial load for legacy scripts i don t think it needs that after page load though i m honestly not sure the primary reason to do this is to disable javascript uris which would be a major method to otherwise bypass this system we also try to regex out links with javascript uris but the regex is sketchy and i don t have great confidence in it the same way i do with the regex for script restrict form action targets to self to reduce risk of scriptless xss that tricks users with forms the main thing this misses is style tags attackers could potentially add them to extract data from a page either by unclosed markup loading a resource that contains the rest of the page in the url or via attacks that use attribute selectors in css so called scriptless xss it also could allow the attacker to make the page display weird in an attempt to trick the user this would be pretty hard to block especially if templatestyles extension is enabled and the risk is relatively quite low as there is not much you can do with it in any case i decided not to care the way the extension hooks into the message class is very hacky if this turns out to be a good idea probably the extension would need to become part of core or new hooks would have to be added to message does it work seems to of course the mere fact i can t hack the thing i myself came up with isn t exactly the greatest brag nonetheless i think it works and i haven t been able to think of any bypasses it also seems to not break anything in my initial testing extension support is a little less clear i think it will work for most extensions that do normal things some extensions probably do things that won t work in most cases they could be fixed by following mediawiki coding conventions in some cases they are intrinsically problematic such as extension widgets to be very clear this hasn t been exhaustively tested so ymmv how many vulns will it stop lets take a look at recent vulnerabilities in mediawiki core taking a look in the vulns in the mediawiki 1 39 release series between 1 39 0 and 1 39 13 there were 29 security vulnerabilities 17 of these vulnerabilities were not xss note that many of these are very low severity to the point its debatable if they even are security vulnerabilities if i was triaging the non xss vulnerabilities i would say there are 6 informational informational is code for i don t think this is a security vulnerability but other people disagree 9 low severity 2 medium low severity none of them come close to the severity of an unauthenticated xss although some may be on par with an xss vuln that requires admin rights to exploit while i haven t explicitly tested all of them i believe the remaining 12 would be blocked by this extension additionally if we are just counting by number this is a bit of an under count as in many cases multiple issues are being counted as a single phab ticket if reported at the same time in conclusion this extension would have stopped 41 of the security vulnerabilities found so far in the 1 39 x release series of mediawiki including all of the high severity ones that s pretty good in my opinion try it yourself you can download the extension from here i d be very curious if you find that the extension breaks anything or otherwise causes unusual behaviour i d also love for people to test it to see if they can bypass any of its protections it should support mediawiki 1 39 and above but please use the rel1_xx for the version of mediawiki you have i e on 1 39 use rel1_39 branch as the master branch is not compatible with older mediawiki posted by bawolff at 8 40 am no comments labels infosec mediawiki wiki friday february 28 2025 explori...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)

Verified site has: 80 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80


The site also has references to the 1 subdomain(s)

  bawolff.net  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Location htt????/blog.bawolff.net/
Content-Type text/html; charset=UTF-8
Content-Encoding gzip
Date Wed, 05 Aug 2026 08:09:53 GMT
Expires Wed, 05 Aug 2026 08:09:53 GMT
Cache-Control private, max-age=0
X-Content-Type-Options nosniff
X-Frame-Options SAMEORIGIN
Content-Security-Policy frame-ancestors self
X-XSS-Protection 1; mode=block
Content-Length 192
Server GSE
Connection close
HTTP/2 200
content-type text/html; charset=UTF-8
expires Wed, 05 Aug 2026 08:09:54 GMT
date Wed, 05 Aug 2026 08:09:54 GMT
cache-control private, max-age=0
last-modified Tue, 02 Jun 2026 03:00:31 GMT
etag W/ 5f051752025b967cfd9cc8d3a01f9fbcd221bbaacb748a22d4b2a3af8ee980be
content-encoding gzip
x-content-type-options nosniff
x-xss-protection 1; mode=block
content-length 34486
server GSE

Meta Tags

title="Bawolff's rants"
content="text/html; charset=UTF-8" http-equiv="Content-Type"
content="blogger" name="generator"
content="htt????/blog.bawolff.net/" property="og:url"
content="Bawolff's rants" property="og:title"
content="A collection of my opinions/rants/whatever else." property="og:description"
name="google-adsense-platform-account" content="ca-host-pub-1556223355139109"
name="google-adsense-platform-domain" content="blogspot.com"
content="htt????/wikiapiary.com/w/images/wikiapiary/2/20/WikiApiary_Logo.png" itemprop="image_url"
content="7338246785946121007" itemprop="blogId"
content="1900664898661684939" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2026/03/giving-wikiapiary-kick.html" itemprop="url"
content="htt???/bawolff.net/blog/f4-cockpit.png" itemprop="image_url"
content="7338246785946121007" itemprop="blogId"
content="8715458080461531405" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/10/pure-css-360-panorama-viewer.html" itemprop="url"
content="7338246785946121007" itemprop="blogId"
content="1365296131915220141" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/10/how-did-xssprotector-do.html" itemprop="url"
content="7338246785946121007" itemprop="blogId"
content="587343727831500915" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/07/preventing-xss-in-mediawiki-new.html" itemprop="url"
content="htt????/upload.wikimedia.org/wikipedia/commons/thumb/f/f9/Arabah_(997008136649905171).jpg/759px-Arabah_(997008136649905171).jpg" itemprop="image_url"
content="7338246785946121007" itemprop="blogId"
content="5693449896938143405" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/02/exploring-structured-data-on-commons.html" itemprop="url"
content="7338246785946121007" itemprop="blogId"
content="8905408103384256646" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/01/happy-belated-new-year.html" itemprop="url"
content="htt????/bawolff.net/bmi.png" itemprop="image_url"
content="7338246785946121007" itemprop="blogId"
content="2342380421374328719" itemprop="postId"
content="htt????/www.blogger.com/profile/02917810358934543942" itemprop="url"
content="htt????/blog.bawolff.net/2025/01/signpost-article-on-calculator.html" itemprop="url"

Load Info

page size34486
load time (s)0.461348
redirect count1
speed download74806
server IP 142.250.110.121
* all occurrences of the string "http://" have been changed to "htt???/"