Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews
View Poll Results: What do you think of the site? (choose all that apply)
Great Job! 0 0%
For what you have said you have done its okay 1 25.00%
Its okay but there were a few mistakes 1 25.00%
The coding is okay but the layout needs work 0 0%
The layout is okay but the coding needs work 2 50.00%
Stop programming now! For gods sake! for love of mankind stop creating this pap! 0 0%
Voters: 4. You may not vote on this poll


Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old July 3rd, 2008, 12:26 PM
borojim borojim is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Jun 2008
Location: 'Yonder hill, where 'pixies live
Posts: 54 borojim User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 12 h 12 m 49 sec
Reputation Power: 1
Send a message via MSN to borojim
Facebook
Talking Thanks everyone - please review http://ttasp.open.ac.uk/~jc22454/ecatest/ab_home.asp

Well I finally managed the coding section of the asp module of my Uni degree (thats a lot of 'of's'!)

So here is a link to the result:

End of Course assignment

Some of the links will take you to a generic 'Under construction' page,

these are:
About Us
Contact Us
Transaction History
Our Services

This is because in the scope of the assignment, They are not required and so have been left under construction.

Certain links are also only available if you are logged in (the catalogue for example)

The idea of this is to create a customer login with a catalogue and shopping cart, using text files as a data source (basically using Text Stream and File System Object) without using databases, with the ability to check for duplicate registration credentials, incorrect login details etc, everything you would expect rm a simple shopping cart, which is what I have done...

I would be grateful if anybody on the board would try the site out, look for dead links, functions that do not work etc as I have to hand this in with my report and I do not want a rubbish grade!

Thanks in advance for any help given

Jimmy

PS, if you register, I would recommend using fake addresses as I have not yet secured the text files correctly yet and at the moment anyone can read them, this is just so I can de-bug at the moment and as soon as I believe it is complete I will secure them so no one can read them.

(don't worry, when it comes to paying insert any 16 digit number as a credit card and it will pass, this is just a sample site after all!)

Reply With Quote
  #2  
Old July 3rd, 2008, 01:11 PM
mystic7 mystic7 is offline
Contributing User
Click here for more information.
 
Join Date: Sep 2006
Posts: 555 mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level)mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level)mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level)mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level)mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level)mystic7 User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 3 Days 19 h 4 m 8 sec
Reputation Power: 39
It's too English It didn't accept my American format phone number. And 57 bucks for a frying pan is a bit steep

Other than that everything seemed to do what it was supposed to do.

Last edited by mystic7 : July 3rd, 2008 at 01:14 PM.

Reply With Quote
  #3  
Old July 4th, 2008, 06:12 AM
Shadow Wizard's Avatar
Shadow Wizard Shadow Wizard is offline
Moderator From Beyond
ASP Free God 46th Plane (27500 - 27999 posts)
 
Join Date: Sep 2004
Location: Israel
Posts: 27,635 Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)Shadow Wizard User rank is General 14th Grade (Above 100000 Reputation Level)  Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1Folding Points: 373781 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 2 Weeks 2 h 55 m 37 sec
Reputation Power: 1902
--moved to Site Reviews forum, that's the proper place to ask members
here to review your website.

feel free to post special thanks in the Lounge.

Reply With Quote
  #4  
Old July 4th, 2008, 08:36 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
1) It's vulnerable to XSS (Cross-Site Scripting) Attacks.
View XSS Attack in Firefox

2) You pass the item price in the URL, so anyone can change the price of an item when it is added to their shopping cart.

3) You have not disabled "autocomplete" on the login form, so this could allow user's credentials to be stolen.

4) Server header shows the app is running on an "Apache/2.0.46 (Red Hat)" server, which has known security vulnerabilities.

5) Standard SQL injection attack (' or 1=1--) placed in the "Customer Login" page, changes the "Login" menu to "Logout", it also ends up displaying the "Customer Services" and "Transaction History" menu items. It appears vulnerable to blind SQL injection.

6) The server responds with a "200 OK" response after log in. Which means user's credentials are stored in the browsers cache.

7) After registration you display the user's login credentials on the screen in clear text.

8) You don't perform proper input validation anywhere.

9) Your shopping cart allows for negative quantities (-1).

10) You store customer info in a cookie in clear text.
Code:
Set-Cookie: AandBPans=Cust=0&Cart=2008545876; expires=Tue, 2-Sep-2008 23:00:00 GMT; path=/


11) Account harvesting is possible via the registration page.

This was all discovered within about 10 minutes of looking at the site.

For more information on how to mitigate these issues, read the articles listed under the "Code Security" section at the link below.

Code Security Articles

Last edited by Memnoch : July 4th, 2008 at 08:39 PM.

Reply With Quote
Reply

Viewing: ASP Free ForumsWeb DesignSite Reviews > Thanks everyone - please review http://ttasp.open.ac.uk/~jc22454/ecatest/ab_home.asp


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway
Stay green...Green IT