Site Reviews
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsWeb DesignSite Reviews

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old September 16th, 2005, 08:07 AM
guymclaren's Avatar
guymclaren guymclaren is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Location: Nelspruit South Africa
Posts: 179 guymclaren User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 1 m 21 sec
Reputation Power: 4
www.lowveldnet.co.za

Re redevelopment of <a href="http://www.lowveldnet.co.za">www.lowveldnet.co.za</a>

Now I know most of you can and will be going on a weekend break or a holiday in the future. I need to redevelop the lowveldnet website into something more useful. I want to add a booking system for local accommodation, attractions and events. I want some feedback as to what you would like to see on such a website.

Is the colour scheme good bad or indifferent?

As to the layout is it easy to understand once you get passed the entry page?

The headings on the top.

I want to seperate accommodation and attractions from the business area as we are going to do bookings for these.

Any suggestions for these titles. I need them to be concise yet easily understood.

My thoughts were

accommodation and activities ( too wordy but decriptive) (description and Booking)
local business (Local Business minisites)
local and travel information (Basic Info as in General Information at present)
Events ( Diary and Booking)
News and Views (Local News and Comments)
Discuss It
Galleries
FAQs
Special Offers
Local and Travel Links
Contact Us
I know I am asking you all to do some work. All criticism and advice will be appreciated.

Regards

Guy
__________________
Guy McLaren
lowveldnet(pty)ltd
Nelspruit, Mpumalanga, South Africa
www.lowveldnet.co.za

Reply With Quote
  #2  
Old September 20th, 2005, 08:09 PM
pws1970 pws1970 is offline
Contributing User
ASP Free Loyal (3000 - 3499 posts)
 
Join Date: Aug 2005
Posts: 3,250 pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)pws1970 User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 20017 Folding Title: Starter FolderFolding Points: 20017 Folding Title: Starter Folder
Time spent in forums: 4 Weeks 1 Day 4 h 5 m 50 sec
Reputation Power: 363
Okay, lets start at the beginning...

Q:Is the colour scheme good bad or indifferent?

A:A resort in the jungle or near a wild reserve is my first impression, so the colour scheme fits the mood, perhaps too much, some neutral colours could be added to break it up.

Q:As to the layout is it easy to understand once you get passed the entry page?

A:The page layout is nearly consistent - did not know which link I was on though sometimes - perhaps consider a map.

Q:The headings on the top.

A:Look really outdated, no rollovers (although this is just presentation I'm talking about here) just need more thought.

Q:Any suggestions for these titles.

A:Keep them low key if you need to emphasise more then that is what the title/alt tag is for.

Other: The right hand menu bar's submenus are just lost - should try a different font color or bgcolor.

Interesting site, very productive, just needs modernised.

Reply With Quote
  #3  
Old September 21st, 2005, 12:11 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
Just an FYI, lowveldnet.co.za, http://www.webtech.co.za and all sites created by this company are vulnerable to SQL Injection attacks.

PLEASE!!! read up on these types of attacks and how to prevent them....your customers won't appreciate their data being stolen.

Reply With Quote
  #4  
Old October 14th, 2005, 01:31 PM
guymclaren's Avatar
guymclaren guymclaren is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Location: Nelspruit South Africa
Posts: 179 guymclaren User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 1 m 21 sec
Reputation Power: 4
OK I am a little thick but a few questions

From my googling I figured I need to boost the security by adding a replace command to prevent people from Injecting and creating their own Passwords.

Am I to understand that if you added to the text box some SQL code you could change the actual SQL Query to be more than I expected?

Also that you can create a page in the address bar that will give a different set of results to those I requested?

In effect is it just changing those two things that will resolve this issue?

Guy


Quote:
Originally Posted by Memnoch
Just an FYI, lowveldnet.co.za, http://www.webtech.co.za and all sites created by this company are vulnerable to SQL Injection attacks.

PLEASE!!! read up on these types of attacks and how to prevent them....your customers won't appreciate their data being stolen.

Reply With Quote
  #5  
Old October 14th, 2005, 01:59 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
It's vulnerable to SQL Injection attacks and parameter manipulation attacks.

These are the only two things I tested.

Reply With Quote
  #6  
Old October 14th, 2005, 02:06 PM
guymclaren's Avatar
guymclaren guymclaren is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Location: Nelspruit South Africa
Posts: 179 guymclaren User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 9 h 1 m 21 sec
Reputation Power: 4
I got that

But what I need to know is.

Is my understanding of the subject flawed?

Am I to look at anything else, I googled and found 4guys most helpful but need to know if I understood the subject.

Guy

Reply With Quote
  #7  
Old October 14th, 2005, 02:13 PM
Memnoch's Avatar
Memnoch Memnoch is offline
Unholy Moderator
ASP Free God 14th Plane (11500 - 11999 posts)
 
Join Date: Oct 2003
Location: In hell, where did you think?
Posts: 11,776 Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)Memnoch User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 3 Weeks 5 Days 8 h 27 m 42 sec
Reputation Power: 470
SQL Injection attacks can occur either from input fields (textboxes,etc...) or passed through the querystring.

How to prevent these attacks depends on the database you are using, the language the application is written in, the web server being used, and the platform the application is running on.

There is no "Simple" solution to preventing these attacks, you have to test for them first. Then research how to prevent them.

There are numerous attacks that can happen against applications (SQL Injection, Parameter Manipulation, XSS, Blind SQL Injection, Hidden Field Tampering, Cookie Hijacking, Session Hijacking, etc...)

You have to learn about each one, test for it, then take the necessary measures to prevent it.

Reply With Quote
Reply

Viewing: ASP Free ForumsWeb DesignSite Reviews > www.lowveldnet.co.za


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT