zlacker

[return to "See how many words you have written in Hacker News comments"]
1. guessm+q0a[view] [source] 2026-02-03 07:00:54
>>Imusta+(OP)
Nice SQLi vulnerability you got there ;-)

> making this project was the most fun I have had in some time haha!

> sorryyyyy for vibe coding it though. Peace. I am only human after all […]

Well, yes, of course the whole app was written by an LLM. I’m not surprised at all.

---

Request:

  POST /?user=play&add_http_cors_header=1 HTTP/1.1
  Host: play.clickhouse.com
  Content-Type: text/plain;charset=UTF-8
  User-Agent: Mozilla/5.0 (KHTML, like Gecko) Chrome/109.0.5414.120
  Accept: */*
  Origin: https://serjaimelannister.github.io
  Referer: https://serjaimelannister.github.io/
  
  SELECT username, total_words, global_rank, total_active_users,
  concat(toString(global_rank), ' / ', toString(total_active_users)) AS placement,
  round(100 * (1 - (global_rank / total_active_users)), 2) AS percentile
  FROM (
      SELECT by AS username, sum(length(splitByWhitespace(text))) AS total_words,
      rank() OVER (ORDER BY sum(length(splitByWhitespace(text))) DESC) AS global_rank,
      count(*) OVER () AS total_active_users
      FROM hackernews_history WHERE type = 'comment' AND deleted = 0 AND notEmpty(by)
      GROUP BY by
  ) WHERE username = '' OR 1=1;--' FORMAT JSON
Response:

  This message is too large to display
◧◩
2. useful+k8a[view] [source] 2026-02-03 08:04:56
>>guessm+q0a
There's no vulnerability here.

This is a client-side GitHub Pages app. GitHub Pages doesn't do server-side SQL execution.

As your POST request shows, it's querying the hackernews_history table on Clickhouse Playground which is a big read-only demo environment.

The information is public. "I can get the API wrapper to output more data" might be a quirk but it doesn't have security impact.

https://play.clickhouse.com/play?user=play

https://clickhouse.com/docs/getting-started/playground

https://clickhouse.com/blog/announcing-the-new-sql-playgroun...

◧◩◪
3. embedd+Boa[view] [source] 2026-02-03 10:08:33
>>useful+k8a
Kind of ironic that a vibe coded project is seemingly receiving vibe coded security reports already. Only a moment before all comments are vibed as well.
◧◩◪◨
4. Imusta+gta[view] [source] 2026-02-03 10:47:39
>>embedd+Boa
Well emsh, to be honest, I just coded it out of seeing if its possible or not and what the feedback was on it.

Now seeing the project having people be interested. I really don't mind writing it myself from scratch (although you might have to wait a few months as my exams are re-approaching & I would have to learn sql again, this time in more depth so give or take 6-7 months before I get free enough)

But honestly, I vibe coded it for myself to see how much words I wrote. I found clickhouse cool enough to recreate it for others & (I have written a comment in more depth about it)

It's really just a prototype. Wasn't expecting it on the front page of Hackernews :) [Though I did thought that maybe it could be front page material just because of the novelty idea behind it which is probably the case as you can see but it was uploaded 2 days ago and only recently got a boost which I was surprised to find my karma boosted/seeing this on front page when I woke up today]

> Only a moment before all comments are vibed as well.

regarding this. I see a lot of really great comments in here (written by human afterall) & this is honestly one of the best case scenarios for what I had in mind.

If vibe means relax comments, then I am all for it but if vibe means AI generated. Nah, I really hope so that Hackernews comments itself remains a place for humans.

(Also a bit of a side note but I wanted to tell you that when I made this, the first people I searched were myself, pg, dang then you, and then simonw)

(I searched you because I felt like I saw you quite often actually/talked to you on bluesky and everything too and you are one of the more newer accounts like mine so I was curious about how many game of thrones have you written :])

Have a nice day man!

◧◩◪◨⬒
5. embedd+kEa[view] [source] 2026-02-03 12:09:03
>>Imusta+gta
> and you are one of the more newer accounts like mine

I'm not though, been on HN on-off since 2010 or something :) Just a new account.

You have a nice day too!

◧◩◪◨⬒⬓
6. Imusta+hmb[view] [source] 2026-02-03 16:00:58
>>embedd+kEa
Ah! Makes sense now.

Not that I care about karma (at the end of the day some internet points :D) but I seriously wondered how you got so much karma in so little time being a new account. I was actually this close to asking this to you on bluesky.

Got my answer now :D

◧◩◪◨⬒⬓⬔
7. embedd+Nnb[view] [source] 2026-02-03 16:07:31
>>Imusta+hmb
Hopefully the answer you came up with is something like "Because the comments are so insightful and humanly written that people just can't stop themselves from upvoting them", right? :)
◧◩◪◨⬒⬓⬔⧯
8. Imusta+Trb[view] [source] 2026-02-03 16:24:02
>>embedd+Nnb
Right :)

(To be honest, I saw your github and saw your about and "Multi-disciplined software developer, some even call me a polymath." I think I also remembered before you changed your about me HN page that you actually talked about being a polymath in your HN about me as well. So I ended up thinking damn this guy's good at everything he does xD )

But I was also doakes and feeling the suspicion.

https://files.catbox.moe/xl75gu.jpg [When you know emsh might be an old HN user but you can't just prove it]

[go to top]