Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,150,047 members, 7,807,141 topics. Date: Wednesday, 24 April 2024 at 10:12 AM

Mtnonline.com XSSed - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Mtnonline.com XSSed (1528 Views)

(2) (3) (4)

(1) (Reply) (Go Down)

Mtnonline.com XSSed by Cactus(m): 8:13am On Sep 03, 2009
So I was reading the job/vacancy board. Then saw a thread about mtn openings. Of course I had to look at it. so the poster gave link to the site which was not complete so easiest thing was to go back to mtnonline.com and click to their career section.

I clicked the career menu then i SCREAMED arghhhhhhhhhhhhhhhhhhhhh. FML. An alert popped up about script injection. So, I dug through several pages of the career section basically that section of their site is messed up. Then I noticed a couple other things

1. mtnonline is built on the .NET Framework
2. the career section = asp
3. by some magically reason, there are sooooooo many nest or deep rooter tr and td
4. the main link to the career page which http://www.mtnonline.com/careers/login.asp  (click at your own risk)  I believe is actually fake because look at the text above the email not proper grammar and the password is not masked. So I guess this was the page code that was either partially replaced or totally reconstructed. If mtnonline actually did this page like that FML.

So, I put together what I found with screenshot and sent it to them and hopefully they will pull it down and fix it asap.
Re: Mtnonline.com XSSed by Afam(m): 8:59am On Sep 03, 2009
These companies and their websites with so many errors.

Sent an email to UBA on my inability to access the Udirect website as the login button doesn't work, have been trying since last week. They responded and confirmed that the address was ok.

I normally use Chrome or Firefox and have been trying to login without any luck. Then it occurred to me it might be a browser compatibility problem and I then fired up IE8 that I have but rarely use and the application worked just fine.

I sent a reply telling them that the application worked when I used IE and made it clear that for a bank it is poor style to have a major application working in a particular browser and not all or most of the browsers out there.
Re: Mtnonline.com XSSed by Cactus(m): 9:17am On Sep 03, 2009
I really don't get why people don't get it.

No need to do cheap stuff. Pay the money and get a great application. No shortcuts. Do it clean and straight really.

I posted an article sometime back about a factory having problems. Trying to solve it in-house they could not and they ended up calling a consultant. And I think the consultant charged 5000$. And the factory manager asked why you changed me so much just to tell me what and where the problem his. And the consultant replied, well, 500$ or so to show you the problem and the remaining because I know what to do. Something like that.

Spend the money geez. Makes everyone happy, customers will be happy and will always come back if they dont experience problems and would likely recommend others to visit. gush
Re: Mtnonline.com XSSed by yawatide(f): 10:46am On Sep 03, 2009
Yep, I might be expensive but it is worth the peace of mind knowing that you are getting a quality product from me and that quality is not compromised cool

Seriously though, I thought stuff like this was a result of cheap clients. Yesterday, we heard from someone who paid millions for service they didn't even get. That tells me that our clients (some anyway) in Nigeria need an education on how the web works. In other words, they shouldn't just take it at face value that when they want a website, they will get what they paid for.

Clients should:
1) Get involved in testing to ensure that they are actually getting what they paid for.

2) Have a contract specifying damages a "webmaster" would pay if they get so many errors (for example say, bugs should not be more than 10% post-launch, which is usually 30 days after the site goes live).

3) Clients should withhold final payment until that say, 30 day threshold has expired, deducting a percentage for each day bugs are not fixed.

Yep, professionalism comes at a price and I am willing to go for months without doing a single job to drive that point home grin

(1) (Reply)

-- / Help Review This Website And Suggest Additional Features / The SEO Wars --- Are Nigerian Bloggers Getting It All Wrong?

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 22
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.