[21:48:00] today i learned there are only three interface admins: the two stewards and myself [21:48:08] i wonder why it is so less common than on miraheze [23:05:36] Naleksuh: It used to be available to any crat, until it was realised that it is incredibly dangerous [23:06:18] Yeah pages like common and skin js/css need to be protected, are there any other known misuses? [23:07:01] no, but someone could have inserted malware [23:07:13] majavah pointed it out [23:08:03] To clarify you mean regular MW pages and not css/js pages right? [23:08:34] not certain [23:09:14] the .js files could have been edited [23:09:19] at the time [23:10:15] which is obviously bad [23:13:26] Yep [23:13:37] Infact I actually recently found a trick to make a keystroke tracker via css [23:13:49] There is a way that every time a certain key is pressed the css queries a certain url [23:14:00] Then simply set up some stuff to log that and bam common.css now used maliciously [23:14:18] yeah, exactly [23:14:28] the example of a cryptominer was also used [23:15:07] That one required js [23:15:16] But yeah uh [23:15:27] miraheze test wiki sure has a loooot of interface admins [23:21:56] that was unprotected [23:22:49] ? [23:24:35] the js could be edited by an IA [23:24:47] Nah common.js is protected at consul level [23:25:45] i mean here [23:26:11] Ah you're right! [23:30:22] And within three days, anyone could have access to it [23:30:48] yeah understood