|
|
|||||||||
|
|||||||||
|
|||||||||
| |
||
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
Www.acotis.co.uk
please leave me some comments and any recommendations as this is my first site.
|
|
#2
|
||||
|
||||
|
//design:
nice design, apart of some minor CSS errors in Firefox. //security: you don't have SSL - you must not make this public until you get secure server, people with keen eyes will notice you lack the SSL and report your website. it's not safe to buy from website such as yours! //general: fatal bug: in the checkout page (basket.asp) if the user is from USA he can't submit because your javascript validation is always telling "you must enter valid state" - after selecting state too... this is really bad, I hope you still don't have any visitors. bottom line, this website is not good and must be fixed before you make it public. |
|
#3
|
|||
|
|||
|
cheers SHADOW, really appreaciate your Help.
I do have SSL when you enter your Credit Card Details (after checkout). Any body else out there please feel free... |
|
#4
|
||||
|
||||
|
having the SSL there is pointless. the sensitive data has already been sent.
sorry for being harsh, but all those problems are better be found now than by visitors. |
|
#5
|
||||
|
||||
|
shadow is right, if shoppers feel anyway in secure, there is a billion other dropship based sites out there, selling the same
SSL 128 bit encryption is less than £30 a yr and i would like to say one point the bold: WE DO NOT ACCEPT ELECTRON VISA why you say that??? and in bold?? it is a negative on the checkout, makes people think hmmmm why is that, strange thing to mention, whats wrong with visa electron ETC ETC then they think no i think i will shop somewere else
__________________
A girl's best asset is her 'lie'ability. For Sale: Parachute. Only used once, never opened, small stain. that fold thing
|
|
#6
|
||||
|
||||
|
Your shopping cart does one of the biggest "No-No's" possible, it stores and passes item prices in hidden fields on the page, which can be manipulated by a hacker.
See the attached image, I was able to manipulate the page and submit a purchase for a £30.00 watch, but my price is only £1.00. |
|
#7
|
||||
|
||||
|
Memnoch, you are good, very good! SQL injection I understand (and there are a surprising amount of sites out there that are vulnerable to it). I also understand how the use of hidden fields leaves open the possibility for a hack - but how exactly do you manipulate these hidden fields?
__________________
LozWare Website Directory Whooo! Free submissions, no recip needed. I'm a nice guy
|
|
#8
|
||||
|
||||
|
Quote:
![]() <rant>funny, I used to use such manipulation to enter into my online bank account with one click, until they blocked it recently. </rant>Last edited by Shadow Wizard : March 22nd, 2006 at 03:37 PM. Reason: typo |
|
#9
|
|||
|
|||
|
Hello, I've also been wondering how to manipulate hidden fields, can someone drop me a PM or something. Thanks
-alex |
|
#10
|
||||
|
||||
|
Quote:
pilonull welcome to the forums ![]() It's more polite for you to PM one of the users involved in such techniques rather than asking them to PM you the info.
__________________
................... ASCII and ye shall receive .................. Knowledge is the only resource on earth that multiplies when shared Support the Shemzilla Project Powered by C# |
|
#11
|
|||
|
|||
|
Quote:
Oh, Thanks for informing me, lol, that's new. Because all the forums i've ever been to have either flamed me for asking something, or told me without explaining things. Ha, well thanks, thats new. And Thanks for welcoming me too. I really like this forum as I'm browsing around. Thanks one more time, -alex |
|
#12
|
||||
|
||||
|
There's nothing wrong with asking how things are done, and should not be reasons to flame over with.
These forums are an excellent resource, as well as a good place to hang out at. Hopefully you'll stick around for a while ![]() |
|
#13
|
|||
|
|||
|
Yep, definately probably will, Nice people so far , hmm, for some reason it is |