|
|
|||||||||
|
|||||||||
|
|||||||||
| |
||
| ||||||||||||||||||||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
Http://www.rhmun.com
This is a site I made for RHMUN, please give any comments or concerns you have towards the site.
http://www.rhmun.com |
|
#2
|
||||
|
||||
|
You need to implement better input validation on the "Register.asp" page. It's Cross-Site Scriptable.
|
|
#3
|
|||
|
|||
|
Lol I just got mass registered by someone....
|
|
#4
|
|||
|
|||
|
By the way, is there anyway for me to set the page to only accept POSTs from my website? So cut off remote POSTs...
|
|
#5
|
||||
|
||||
|
Yes, you can reduce the chance of remote POSTs by checking the Referrer header and making sure the value is from your site, but that won't prevent it completely as the Referrer header can be manipulated...I was the one that did the mass register and it was remote and I modified the referrer header...
![]() |
|
#6
|
|||
|
|||
|
Evil... xD
Anyway, try again, I researched a lot on the safety of the site. Took me a lot of work, I think it's safer now, even if there's still leaks, the page now records every ip that visits it... |
|
#7
|
||||
|
||||
|
Nope, the page is still vulnerable to an XSS attack.
If I were doing the site I would whitelist the acceptable input into those fields. |
|
#8
|
|||
|
|||
|
Can you please specify? I Googled "ASP whitelist" and got a bunch of irrelevant results.
|
|
#9
|
||||
|
||||
|
It's not "ASP Whitelist" it's just whitelist.
It's basically an input validation technique that ensures only acceptable characters are allowed in the fields. For example, You would only allow characters a-z in the first name field. You would only allow characters a-z, ' (apostrophe), and - (hyphen) in the last name field. For a basic zip code you would only allow 5 digits in the zip code field. This is whitelisting. And the validation should be done on both the client and the server. |
|
#10
|
|||
|
|||
|
Hmmm great I worked on that. Any comments for the design?
|
|
#11
|
||||
|
||||
|
Sorry, I don't do design, only security.
|
|
#12
|
|||
|
|||
|
Hi;
I have visited your site and I think it look good. Good luck to you. ![]() |
|
#13
|
|||
|
|||
|
Thank you. xD
|
|
#14
|
||||
|
||||
|
in your Contact Us page, the mail addresses are not clickable.
usually when user see an email address, he/she should be able to click this and send email. this is done by pure HTML: Code:
<a href="mailto:email@domain.com">email@domain.com</a> you can learn more by Googling the word "mailto". the rest of the site looks fine, nice and simple design. |
|
#15
|
|||
|
|||
|
Thank you shadow. The reason why I did not use mailto is because I personally find it unhandy. People around me don't use any software clients like Outlook, so it would be inconvinient if anyone accidentally clicked it when they just wanted to copy and paste. =)
|
![]() |
| Viewing: ASP Free Forums > Web Design > Site Reviews > Http://www.rhmun.com |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|
|