On Tue, Aug 12, 2008 at 8:22 AM, Aleksej deletesoftware@yandex.ru wrote:
Gregory Maxwell wrote:
There are no centeral auth tokens on wikimedia.org for a reason! :)
What about secure.wikimedia.org?
What about it? Many of the subdomains have tokens, but wikimedia.org itself does not. Secure, unfortunately, does not result in images being transferred via HTTPS.
(though good work by Daniel in figuring out how to exploit it using file path)