Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old August 26th, 2005, 02:26 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Buzzcard International Calling Card

I am not sure i wanna so this but i guess it is better to konw than not to!

Memnoch -- please be kind as the site is live and has been for a while. Thanks

www.buzzcard.co.uk

Reply With Quote
  #2  
Old August 26th, 2005, 02:47 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,764 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 6 h 9 m
Reputation Power: 452
1) You're escaping single quotes, that's the first step in preventing sql injection.

2) You should do some client-side validation on the Payments2.php and Payments3.php forms.

3) You should set the MaxLength property on all of your input fields to prevent a user form entering thousands of characters into a field. This can lead to overflow errors or type mismatch errors.

4) You are using hidden variables on your submit to "HSBC" page. This allows someone to manipulate the values of those fields, but as long as you or the HSBC site is validating the values, it shouldn't be a major concern.

Reply With Quote
  #3  
Old August 26th, 2005, 02:50 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Quote:
Originally Posted by Memnoch
1) You're escaping single quotes, that's the first step in preventing sql injection.

2) You should do some client-side validation on the Payments2.php and Payments3.php forms.

3) You should set the MaxLength property on all of your input fields to prevent a user form entering thousands of characters into a field. This can lead to overflow errors or type mismatch errors.

4) You are using hidden variables on your submit to "HSBC" page. This allows someone to manipulate the values of those fields, but as long as you or the HSBC site is validating the values, it shouldn't be a major concern.

Thanks Memnoch, that is all appreciated.

So 1) is good then.
2)i check that they enter the required fields but i think that is it. I need to check the email is correct but not sure what else you would suggest?
3)ok, i will set the max length as you suggest.
4) yes, there is validation. We send across a hash of the data and then at hsbc the data sent is hased and the hasses are compared so that should be ok!

thanks again very much, it is appreciated. So not too bad then??? Be honest...

Thanks

RF

Reply With Quote
  #4  
Old August 26th, 2005, 02:53 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,764 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 6 h 9 m
Reputation Power: 452
You also might consider changing the name of your admin side...www.mydomain.com/admin is the first place a hacker will look to gain access to your site.

Not bad, it's a nice looking site and I didn't seen anything that would make it easily vulnerable.

But, I also haven't tried everything on it, I just did some basic attempts at sql injection and some other tests.
Comments on this post
RadioactiveFrog agrees: Thank you very much for looking at that and for your helpful responses!

Last edited by Memnoch : August 26th, 2005 at 02:56 PM.

Reply With Quote
  #5  
Old August 26th, 2005, 02:56 PM
RadioactiveFrog's Avatar
RadioactiveFrog RadioactiveFrog is offline
Senior Glowing Wizard
ASP Free God 7th Plane (8000 - 8499 posts)
 
Join Date: May 2005
Location: Sussex
Posts: 8,203 RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)RadioactiveFrog User rank is Captain (20000 - 30000 Reputation Level)  Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1Folding Points: 157641 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 4 Days 39 m 12 sec
Reputation Power: 291
Send a message via MSN to RadioactiveFrog
Facebook
Quote:
Originally Posted by Memnoch
You also might consider changing the name of your admin side...www.mydomain.com/admin is the first place a hacker will look to gain access to your site.

Not bad, it's a nice looking site and I didn't seen anything that would make it easily vulnerable.

But, I also haven't tried everything on it, I just did some basic attempts at sql injection and some other tests.
ok thanks for that it is appreciated. I will make the changes as you suggest and i will rename the admin site. That will confuse my colleague!!!!

Thanks again very much.

rF

Reply With Quote
Reply

Viewing: ASP Free ForumsWeb DesignSite Reviews > Buzzcard International Calling Card


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT