Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old March 30th, 2005, 10:39 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Take a look at my site ( http://www.btdb.org)

Its still very much in development. But i've been working on it off and on for about 6 months.

http://www.btdb.org


On a sidenote, i find it humorous that an ASP message board is written in PHP.

Reply With Quote
  #2  
Old March 31st, 2005, 02:29 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,760 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 5 h 22 m 16 sec
Reputation Power: 443
Quote:
Originally Posted by nmajdan
On a sidenote, i find it humorous that an ASP message board is written in PHP.

It's more than just an ASP message board and I find it humorous to have been able to hack into your Admin side in less than 10 seconds.

Reply With Quote
  #3  
Old March 31st, 2005, 03:32 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Quote:
Originally Posted by Memnoch
It's more than just an ASP message board and I find it humorous to have been able to hack into your Admin side in less than 10 seconds.


well you're kind of an ***. i wasnt trying to make a rude comment. thanks for the suggestions for improvements.

Reply With Quote
  #4  
Old March 31st, 2005, 04:41 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,760 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 5 h 22 m 16 sec
Reputation Power: 443
I wasn't trying to be rude, I was just being sarcastic.
If you would like any details on how I hacked it let me know.

Reply With Quote
  #5  
Old March 31st, 2005, 04:48 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Quote:
Originally Posted by Memnoch
I wasn't trying to be rude, I was just being sarcastic.
If you would like any details on how I hacked it let me know.


ok. just clarifying.

yes, i would love to know. you can email me at nmajdan@yahoo.com. this is my first real asp site. i'm sure there are a lot of vulnerabilities. but thanks for the help.

Reply With Quote
  #6  
Old April 15th, 2005, 08:15 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
how do i make my admin page more secure?

Reply With Quote
  #7  
Old April 16th, 2005, 08:56 AM
Phoenix's Avatar
Phoenix Phoenix is offline
Web-Standards Evangelist
ASP Free Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2003
Posts: 1,522 Phoenix User rank is Corporal (100 - 500 Reputation Level)Phoenix User rank is Corporal (100 - 500 Reputation Level)Phoenix User rank is Corporal (100 - 500 Reputation Level)Phoenix User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 4 Days 23 h 48 m 4 sec
Reputation Power: 8
  • Sanitive form data input (prevents SQL injection, which is probably how Memnoch owned your application)
  • Protect "admin" or private directories at file-system level, then server level, finally, appliction level (In a WISA system, that's NTFS Perms, IIS Secs, and ASP Authentication respectivly)
  • Never link to an "admin" page or section from a publicly available page
  • Never call the admin backend directory or files something like "admin", name it something less obvious or a string of random characters
  • And stuff
Just google for "hardening web applications"

Reply With Quote
  #8  
Old April 16th, 2005, 11:00 AM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Quote:
Originally Posted by 1337_d00d
  • Sanitive form data input (prevents SQL injection, which is probably how Memnoch owned your application)
  • Protect "admin" or private directories at file-system level, then server level, finally, appliction level (In a WISA system, that's NTFS Perms, IIS Secs, and ASP Authentication respectivly)
  • Never link to an "admin" page or section from a publicly available page
  • Never call the admin backend directory or files something like "admin", name it something less obvious or a string of random characters
  • And stuff
Just google for "hardening web applications"



ok, thanks i'll google it. i dont quite understand those first two yet, but i'll look it up. the last two i've thought about before, and i will probably do that. i'll take the admin link off my site and rename the admin.asp file something more similar to what i would a password. thanks.

Reply With Quote
  #9  
Old April 16th, 2005, 12:28 PM
lewy's Avatar
lewy lewy is offline
Alter Ego Wizard
ASP Free Specialist (4000 - 4499 posts)
 
Join Date: Jun 2004
Location: Edinburg Tx
Posts: 4,376 lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)lewy User rank is General 6th Grade (Above 100000 Reputation Level)  Folding Points: 1009 Folding Title: Novice Folder
Time spent in forums: 1 Month 1 Week 1 Day 21 h 21 m 31 sec
Reputation Power: 1391
In addition to that, why not take off the admin login to your site from your user pages.
Just create another page in which only you the Web master knows the Admin login is.
I really think that by adding an admin page where it's visible, ppl are going to try and hack it.
My admin pages are totally separated from where the content is, furthermore, it is good practice not to call it admin, make up some name that you will remember like was.asp short for web admin side.asp
You get the idea
HTH
__________________
................... ASCII and ye shall receive ..................
Knowledge is the only resource on earth that multiplies when shared


Support the Shemzilla Project
Powered by C#

Reply With Quote
  #10  
Old April 16th, 2005, 12:49 PM
gregory.owen@hp's Avatar
gregory.owen@hp gregory.owen@hp is offline
Maniac
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2003
Location: Sweet Home, Oregon
Posts: 548 gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 4 h 37 m 8 sec
Reputation Power: 13
Quote:
Originally Posted by nmajdan
Its still very much in development. But i've been working on it off and on for about 6 months.

http://ccc.domaindlx.com/nmajdan/bt




The first thing I notice is that my javascript debugger yells at me for a syntax error in line 5 character 1. Looking at your source, I didn't see any javascript or include files that early in the page, so I don't know where that's comming from.

The color scheme is hard on my eyes (but then, I'm a bit older than your likely target audience at 34.)

Reply With Quote
  #11  
Old April 16th, 2005, 06:31 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Quote:
Originally Posted by gregory.owen@hp
The first thing I notice is that my javascript debugger yells at me for a syntax error in line 5 character 1. Looking at your source, I didn't see any javascript or include files that early in the page, so I don't know where that's comming from.

The color scheme is hard on my eyes (but then, I'm a bit older than your likely target audience at 34.)


yeah, there is not javascript in my code except for the the bit of code at the bottom that is supposed to be for traffic tracking, but doesnt work.

i've been torn on the coloring scheme, and it looks better on some monitors then others so that may be something i have to look at in the future.

Reply With Quote
  #12  
Old April 17th, 2005, 12:17 AM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
thanks to those of you who hacked my site, broadcasted it, and didnt bother advising me on how to correct my inadequacies.

Reply With Quote
  #13  
Old April 17th, 2005, 06:17 PM
gregory.owen@hp's Avatar
gregory.owen@hp gregory.owen@hp is offline
Maniac
ASP Free Novice (500 - 999 posts)
 
Join Date: Sep 2003
Location: Sweet Home, Oregon
Posts: 548 gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level)gregory.owen@hp User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 4 h 37 m 8 sec
Reputation Power: 13
Quote:
Originally Posted by nmajdan
yeah, there is not javascript in my code except for the the bit of code at the bottom that is supposed to be for traffic tracking, but doesnt work.

i've been torn on the coloring scheme, and it looks better on some monitors then others so that may be something i have to look at in the future.

Yeah, I am using a laptop. It would look better on a crt.

Reply With Quote
  #14  
Old May 6th, 2005, 11:22 AM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Ok. I tried some stuff as far as admin access goes. Is it any better now?

Reply With Quote
  #15  
Old May 15th, 2005, 05:34 PM
nmajdan nmajdan is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2004
Posts: 158 nmajdan User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 10 h 19 m 16 sec
Reputation Power: 0
Quote:
Originally Posted by nmajdan
Ok. I tried some stuff as far as admin access goes. Is it any better now?


i'm hoping so by the lack of responses.

Reply With Quote
Reply