@invalid-usernames

i follow users who have usernames that can no longer be made (1-3chars, users with dots etc)
Wall

credit to @up

2char list of things that haven't been archived yet

en, eq, er, ev, ew, ex, ez, ff, fr, fw, fx, gg, gn, go, ha, hd, he, hg, hh, hi, hj, hk, hm, hp, id, if, ii, il, im, in, io, ip, iq, is, it, ja, jb, je, ji, jj, jk, jm, jr, js, kk, ko, lb, le, lg, li, lk, ll, lo, lt, lu, lv, ly, mc, md, me, mf, mi, mj, mk, ml, mm, mn, mo, mr, my, nb, ng, nn, no, nz, oc, of, og, oh, oi, oj, ok, on, oo, op, or, os, ox, pd, pi, pn, pp, pq, pr, ps, qa, qe, qi, qq, qw, qz, rf, rg, rm, rn, rr, sa, sc, sd, sg, so, ss, st, tb, tm, tn, to, ts, tt, tu, tv, ty, uh, ui, uk, um, up, us, uu, vb, zj, vc, vp, vv, vx, wa, we, wm, wo, wp, ws, ww, xd, xk, xp, xu, xx, xy, xz, ya, ye, yk, ym, yo, yt, yw, yy, yz, za, zj, zt, zu, zx, zz, 1k, 1m, 3k, 4u, g0, g1, v1, l2, g3

Jul 26, 2024, 9:06 PM
2 1 34
‹‹ 321 ››

rarest name ever is probably @🥬 (i think it was that emoji) or @:)

what's the rarest invalid username on here?

i would think either @/wasteof.money or @/david (admin) but there might be others i don't know about

2 days ago
2 0 1

if someone could do a few of those that would really help out, thanks!

credit to @up

2char list of things that haven't been archived yet

en, eq, er, ev, ew, ex, ez, ff, fr, fw, fx, gg, gn, go, ha, hd, he, hg, hh, hi, hj, hk, hm, hp, id, if, ii, il, im, in, io, ip, iq, is, it, ja, jb, je, ji, jj, jk, jm, jr, js, kk, ko, lb, le, lg, li, lk, ll, lo, lt, lu, lv, ly, mc, md, me, mf, mi, mj, mk, ml, mm, mn, mo, mr, my, nb, ng, nn, no, nz, oc, of, og, oh, oi, oj, ok, on, oo, op, or, os, ox, pd, pi, pn, pp, pq, pr, ps, qa, qe, qi, qq, qw, qz, rf, rg, rm, rn, rr, sa, sc, sd, sg, so, ss, st, tb, tm, tn, to, ts, tt, tu, tv, ty, uh, ui, uk, um, up, us, uu, vb, zj, vc, vp, vv, vx, wa, we, wm, wo, wp, ws, ww, xd, xk, xp, xu, xx, xy, xz, ya, ye, yk, ym, yo, yt, yw, yy, yz, za, zj, zt, zu, zx, zz, 1k, 1m, 3k, 4u, g0, g1, v1, l2, g3

Jul 26, 2024, 9:06 PM
2 1 34

L banned

also @jeffalo if you want to know a REAL security issue, you can change your password to blank and make accounts with no passwords. here’s one i just created: wasteof.money/$66d2ee2b7a4a6e673f8aaf76

there are probably >90 of these accounts (most banned) and considering really big lists of users have been created it would probably not be too hard to attempt to hack a bunch of them, by logging in without a password. soo… maybe fix this issue?

warning!

From the tests i have done, there are many vulnerabilities on this website, there are also a lot of bugs. Example: when posting something, if you spam click `post` it will create a post for every time you click the button, there should be an implementation to limit the time between posts and to make the button a one time click. (THIS BUG MAKES THE SITE LAG!). its also a pain to delete all of the posts if you accidentally do so as the site refreshes but will still lag and there is a small chance that the post will not be deleted. There is also a password vulnerability… maybe don’t have the user’s passwords get stored as a plain document.

THERE ARE VULNERABILITIES IN THE REPO!; Yes, even tho the repo is the legacy site and isn’t used anymore it is still good to state the vulnerabilities on the repo as people might use the template to make their own site like this and wont know of the vulnerabilities in the code:

List of the vulnerabilities on the repo: SQL Injection, Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), Lack of Input Validation, Insecure, Outdated Dependencies, Lack of Error Handling, Insecure Session Managemen, Storage of Sensitive Data(user and password information: Insecure Password Storage, Weak Password Hashing, Lack of Password Salting, Insecure Password Verification, Missing Password Complexity Requirements, insecure Password Reset Token Generation, insecure Password Storage in Sessions), Lack of Secure Communication… sry <3

nooo my username changed back

THE COMPLETE 2CHAR LIST (?)

With lots of help from @up

(Look in the comments, it’s too big)

what's the rarest invalid username on here?

i would think either @/wasteof.money or @/david (admin) but there might be others i don't know about

btw yes this is an alt

but don't bother asking whose

(not ayd though)

credit to @up

2char list of things that haven't been archived yet

en, eq, er, ev, ew, ex, ez, ff, fr, fw, fx, gg, gn, go, ha, hd, he, hg, hh, hi, hj, hk, hm, hp, id, if, ii, il, im, in, io, ip, iq, is, it, ja, jb, je, ji, jj, jk, jm, jr, js, kk, ko, lb, le, lg, li, lk, ll, lo, lt, lu, lv, ly, mc, md, me, mf, mi, mj, mk, ml, mm, mn, mo, mr, my, nb, ng, nn, no, nz, oc, of, og, oh, oi, oj, ok, on, oo, op, or, os, ox, pd, pi, pn, pp, pq, pr, ps, qa, qe, qi, qq, qw, qz, rf, rg, rm, rn, rr, sa, sc, sd, sg, so, ss, st, tb, tm, tn, to, ts, tt, tu, tv, ty, uh, ui, uk, um, up, us, uu, vb, zj, vc, vp, vv, vx, wa, we, wm, wo, wp, ws, ww, xd, xk, xp, xu, xx, xy, xz, ya, ye, yk, ym, yo, yt, yw, yy, yz, za, zj, zt, zu, zx, zz, 1k, 1m, 3k, 4u, g0, g1, v1, l2, g3

Jul 26, 2024, 9:06 PM
2 1 34
  1. 2char.wasteof.me

  2. if someone wants to continue the archiving project, the next one is @da and onwards

car licence plates are quite cool

if someone wants to make my life easier, i'm currently at @bf in archiving 2letter accounts alphabetically

if you want to, you can continue archiving accounts alphabetically - just tell me where you got to please :)

  1. https://wasteof.money/favicon.ico

  2. finished archiving all the 2nums!!! this is so good so much work finished now i’m on the the 2Ls

all 2nums up to @66 have been archived

also, does anyone have any info on who made @dead?

‹‹ 321 ››