On Jan 24, 2009, at 6:18 PM, Sophie wrote:

>>> (Hm... will usernames that start with "xn__" be allowed? Then people
>>> could register, say, xn__lite_9oa as their username, resulting in a
>>> subdomain of élite.dreamwidth.org.)
>>
>> Hmmm, yeah, those should be disallowed.
>
> Should they? I can see some great applications of those. I think the
> point being made was that such names would be quite useful.


It's a very common XSS injection route.

--D


--  
Denise Paolucci
[email protected]
Dreamwidth Studios: Open Source, open expression, open operations.  
Coming soon!

_______________________________________________
dw-discuss mailing list
[email protected]
http://lists.dwscoalition.org/cgi-bin/mailman/listinfo/dw-discuss

Reply via email to