Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old January 12th, 2008, 06:51 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Http://www.rhmun.com

This is a site I made for RHMUN, please give any comments or concerns you have towards the site.

http://www.rhmun.com
__________________
Why Captcha Images Are EVIL!


For more interesting reads, visit 3Or2-3.

Reply With Quote
  #2  
Old January 12th, 2008, 08:02 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 15th Plane (12000 - 12499 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 12,025 Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 12 h 21 m 3 sec
Reputation Power: 628
You need to implement better input validation on the "Register.asp" page. It's Cross-Site Scriptable.

Reply With Quote
  #3  
Old January 12th, 2008, 10:14 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Lol I just got mass registered by someone....

Reply With Quote
  #4  
Old January 12th, 2008, 10:37 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
By the way, is there anyway for me to set the page to only accept POSTs from my website? So cut off remote POSTs...

Reply With Quote
  #5  
Old January 13th, 2008, 01:36 AM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 15th Plane (12000 - 12499 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 12,025 Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 12 h 21 m 3 sec
Reputation Power: 628
Yes, you can reduce the chance of remote POSTs by checking the Referrer header and making sure the value is from your site, but that won't prevent it completely as the Referrer header can be manipulated...I was the one that did the mass register and it was remote and I modified the referrer header...

Reply With Quote
  #6  
Old January 13th, 2008, 11:01 AM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Evil... xD
Anyway, try again, I researched a lot on the safety of the site. Took me a lot of work, I think it's safer now, even if there's still leaks, the page now records every ip that visits it...

Reply With Quote
  #7  
Old January 15th, 2008, 09:18 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 15th Plane (12000 - 12499 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 12,025 Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 12 h 21 m 3 sec
Reputation Power: 628
Nope, the page is still vulnerable to an XSS attack.

If I were doing the site I would whitelist the acceptable input into those fields.

Reply With Quote
  #8  
Old January 16th, 2008, 12:37 AM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Can you please specify? I Googled "ASP whitelist" and got a bunch of irrelevant results.

Reply With Quote
  #9  
Old January 16th, 2008, 11:01 AM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 15th Plane (12000 - 12499 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 12,025 Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 12 h 21 m 3 sec
Reputation Power: 628
It's not "ASP Whitelist" it's just whitelist.
It's basically an input validation technique that ensures only acceptable characters are allowed in the fields.

For example,
You would only allow characters a-z in the first name field.
You would only allow characters a-z, ' (apostrophe), and - (hyphen) in the last name field.
For a basic zip code you would only allow 5 digits in the zip code field.

This is whitelisting.

And the validation should be done on both the client and the server.

Reply With Quote
  #10  
Old January 19th, 2008, 12:56 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Hmmm great I worked on that. Any comments for the design?

Reply With Quote
  #11  
Old January 19th, 2008, 04:54 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 15th Plane (12000 - 12499 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 12,025 Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level)Memnoch User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 3 Weeks 6 Days 12 h 21 m 3 sec
Reputation Power: 628
Sorry, I don't do design, only security.

Reply With Quote
  #12  
Old March 5th, 2008, 03:25 AM
Puerto Puerto is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Feb 2008
Posts: 1 Puerto User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 m 13 sec
Reputation Power: 0
Hi;

I have visited your site and I think it look good.

Good luck to you.


Reply With Quote
  #13  
Old March 16th, 2008, 07:46 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Thank you. xD

Reply With Quote
  #14  
Old March 18th, 2008, 10:15 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is online now
Moderator From Beyond
Click here for more information
 
Join Date: Sep 2004
Location: Israel
Posts: 29,270 Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 23rd Grade (Above 100000 Reputation Level)  Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2Folding Points: 588205 Folding Title: Super Ultimate Folder - Level 2
Time spent in forums: 3 Months 2 Weeks 2 Days 47 m 39 sec
Reputation Power: 2509
in your Contact Us page, the mail addresses are not clickable.
usually when user see an email address, he/she should be able
to click this and send email.

this is done by pure HTML:
Code:
<a href="mailto:email@domain.com">email@domain.com</a>

you can learn more by Googling the word "mailto".

the rest of the site looks fine, nice and simple design.

Reply With Quote
  #15  
Old March 18th, 2008, 02:51 PM
icywave icywave is offline
Contributing User
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2005
Location: Global Village
Posts: 719 icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level)icywave User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 5 Days 4 h 15 m 41 sec
Reputation Power: 52
Send a message via MSN to icywave
Thank you shadow. The reason why I did not use mailto is because I personally find it unhandy. People around me don't use any software clients like Outlook, so it would be inconvinient if anyone accidentally clicked it when they just wanted to copy and paste. =)

Reply With Quote
Reply

Viewing: ASP Free ForumsWeb DesignSite Reviews > Http://www.rhmun.com


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump





 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 2 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek