Hacker Newsnew | past | comments | ask | show | jobs | submit | MeProtozoan's commentslogin

Proof of concept made by a few friends of me.

Install the Surround Video app (https://appsto.re/nl/QdvDL.i) and use your iPhone/iPad as a Oculus rift alternative.


Bugs I've found:

Fix the user input for domainnames: I'm able to enter non ascii chars

XSS: http://www.co.vu/search?domain=<marquee>; http://www.co.vu/dnssettings/createrecord?domain=%3E%3Cmarqu...

Full path disclosure (and maybe even SQL injections possible): http://www.co.vu/dnssettings?domain=

Access other users DNS (even without login): http://www.co.vu/dnssettings/dnsrecords?domain=notmydomain

OpenDir (showing server software used): http://www.co.vu/img/posterous/


Thanks will do it


www.co.vu is 'available for registration' ;-)


I am working on the restricted list of domains. Just wanted to validate the app. Before fixing few things


Any rough date on when it's gonna get Nameserver support?


Very Soon. First will fix most of the security issues and roll out the new features. Will notify you.

Thanks


This is against the API rules of Facebook, remove it asap.


What part of the Tos? The app is explicitly asking you for permission to post things to your wall.


Mmm why not use http://WikInstant.com ?


can't there be more than one instant wikipedia? yours loads the article directly, whilst mine loads related articles when typing, with a snippet of what they are about.

mine is faster in case you just want to know what something is and not everything about that. and mine also shows related results that may be of interest, or not.


I prefer the direct load because the 1st hit is almost everytime the page I would like to read. For example I use http://WikInstant.com for college (i.e. quickly looking up diseases), WikInstant.com is perfect for that doesn't require me to use the mouse (compared to other wiki instant sites).


Nice found! Also check http://WikInstant.com (built that one a few days ago)


Thanks for the feedback Eitally!

It does a fulltext search so the "I'm feeling lucky" is only while typing. In case everything fails an autosubmit will be done on the regular search engine of wikipedia. Can you give me an example of a frustrating situation which is not a problem when using the old fashioned search?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: