Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,151,911 members, 7,814,076 topics. Date: Wednesday, 01 May 2024 at 05:45 AM

Site Review (security Analysis) - Gamecdswap - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Site Review (security Analysis) - Gamecdswap (725 Views)

Lagoslabs.com Site Review / Colorbox / Thickbox / Critical Site Review / Site Review: Naija Lingo (pidgin English Dictionary) (2) (3) (4)

(1) (Reply) (Go Down)

Site Review (security Analysis) - Gamecdswap by DualCore1: 8:05am On Oct 16, 2010
Ok, let me just come straight. Slyr0x, i spent about a week painfully coding this up with as much security consciousness as I could have. Oya do your thing, pls. smiley

Link
http://sawyerrken.net/clients/gamecdswap/

Test account:
Username: sawyerrken
Password: sawyerrken

if anyone changes the password to test it, change it back to sawyerrken after testing abeg.

Description:
A site where people place Video game CDs they have for exchange.

Features:
Ability to add, view, delete game CD exchanges.
Ability to view member profile and also rate them.
Private Messaging among members
Game CD search based on Game name or location of Game CD owner
News board that can be editted and controlled by site admin


Slyr0x, one more thing: Check the site and assume you didnt know I was the one who did it, then tell me what server side language I used.
I think that's all.

It is my hope that no vuln is found undecided
Re: Site Review (security Analysis) - Gamecdswap by ogzille(m): 8:34am On Oct 16, 2010
chai! i wanted to make some comments but , cry cry

oya , Slyr0x over to you.
Re: Site Review (security Analysis) - Gamecdswap by Nobody: 8:53am On Oct 16, 2010
As you don put slyrox. Tasty reviewers like us have been put out of business!
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 9:18am On Oct 16, 2010
na wa o. I am accepting reviews from everyone joor. Babes can review too.
Re: Site Review (security Analysis) - Gamecdswap by cmon(m): 11:53am On Oct 16, 2010
Nice layout and the owner of the site has a nice concept too.

My Review;

1. I tried editing a field after logging in but when I clicked on the field, all the initial text written disappeared. Leaving me a blank field. What if I just wanted to correct a simple spelling error. Does it mean I'll have to retype everything? Also it happened when I tried to edit my profile. It can drive someone who's just trying to change a character nuts

2. If I'm to send a message to admin and I mistakenly didn't fill the subject field, my entire message is lost. You need to enable some session to store my already typed text.

3. Lastly I think it will be cool if I can just click the username of a CD owner to PM him.

That's just it from it.

But really, I think the concept will sell. It's simple. Good work.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 12:37pm On Oct 16, 2010
Cmon, thanks.

Points 1 and 2 and been taken care of. You can check again and let me know if it feels better.

Point 3, an interested exchanger may want to know some background info about the owner before PM'ing him so that's why I am sending him to the profile so he can see the guy's rating, location, contact e.t.c.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 1:00pm On Oct 16, 2010
Ogzille try o. I dey see your "drop table" handwork. :-P
Re: Site Review (security Analysis) - Gamecdswap by sayhi2ay(m): 2:07pm On Oct 16, 2010
- put recent games on the dashboard
- change timestamp to 12 hours
- don't make me confirm that I indeed want to edit a message or save, I know what I clicked!
- categorize game types, Ps2, ps3 wii etc etc
- aggregate your ratings, you can create a modal box to show rating break down, n I will click it if I care to know
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 2:09pm On Oct 16, 2010
Thanks, will work on all your suggestions.
Re: Site Review (security Analysis) - Gamecdswap by sayhi2ay(m): 2:15pm On Oct 16, 2010
Np. Not tested the functionalities though, checked from iPad.
Why not make it open source if you are not developing for a client?
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 2:23pm On Oct 16, 2010
Its for a client.
Re: Site Review (security Analysis) - Gamecdswap by hostmot(f): 3:40pm On Oct 16, 2010
That is a well developed site,

but has your client worked out the logistics involved in carrying out the CD exchanges or will the members be handling that on their own?
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 3:46pm On Oct 16, 2010
Thanks. smiley
He plans to leave that for the exchanging parties to decide. Will put up a disclaimer shortly.
Re: Site Review (security Analysis) - Gamecdswap by Dizzy001(m): 4:00pm On Oct 16, 2010
nyc
no problems wif it but the following details should be important

category of the c.d(genre,console)
date game c.d was bought
why you want to exchange/swap
then a check box for "scratches" (yes or no)
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 7:11pm On Oct 16, 2010
sayhi2ay:

- put recent games on the dashboard
- change timestamp to 12 hours
- don't make me confirm that I indeed want to edit a message or save, I know what I clicked!
- categorize game types, Ps2, ps3 wii etc etc
- aggregate your ratings, you can create a modal box to show rating break down, n I will click it if I care to know

Thanks, I have categorised games now. I have also added to the Admin panel the ability to add, edit and delete game categories. Then I have added "Console" to the side bar search criteria so users can search for games based on the desired console.

Dizzy001:

date game c.d was bought
why you want to exchange/swap
then a check box for "scratches" (yes or no)

Thanks bro. I have taken care of this on the "Add Games" page. It instructs them to add all these and other necessary info to the description field.


Meanwhile, slyr0x is no where to be found. Earlier on my server kicked out his IPs when he tried his voodoo. I removed him from the blacklist. He's found his way into the blacklist again this time for "port scanning" offenses. tongue
Re: Site Review (security Analysis) - Gamecdswap by Slyr0x: 9:19pm On Oct 16, 2010
Dual Core:

Meanwhile, slyr0x is no where to be found. Earlier on my server kicked out his IPs when he tried his voodoo. I removed him from the blacklist. He's found his way into the blacklist again this time for "port scanning" offenses. tongue

Sorry i had sm stuffs to settle offline, jst came Online now. Then to your 'Over-sabi' firewall, wetin dey do am? U shoulda told it i was a 'legal attacker'. grin grin

Nywaiz, i'll try cloaking, lets see as it goes + I dnt have access as the pwd 'sawyerrken' has been changed.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 9:31pm On Oct 16, 2010
Lol sorry, the firewall work dey do wetin i send am. The sawyerrken password has been reset to sawyerrken
Re: Site Review (security Analysis) - Gamecdswap by Slyr0x: 10:59pm On Oct 16, 2010
U using PHP/5.2.14 ?

+

Check ur logs + It seems your over-sabi firewall is at it again. Still bouncing my connection around tho.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 11:13pm On Oct 16, 2010
Lol, the firewall has blocked an entire block of your IP.
41.***.*8.0/24

Mail me a list of your IPs, let me add a temporary rule to ignore them. Php version correct. 1+
Re: Site Review (security Analysis) - Gamecdswap by Slyr0x: 11:35pm On Oct 16, 2010
Yeah, thats d range. From 41.***.*8.0 - 41.***.*8.255.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 11:44pm On Oct 16, 2010
Range is clear now. Go in nice and steady.

Stupiid question: Does this in effect mean my present firewall config will go a long way to stop the real exploits? Pls ansa.

I'll be online for the next couple of hours so holla me when you done so I can take off the ignore rule.
Re: Site Review (security Analysis) - Gamecdswap by Slyr0x: 12:01am On Oct 17, 2010
answer : yeah it will buh there lotta ways to bypass it.

Read here --> http://www.pisa.org.hk/event/bypassfw.pdf

I'll buzz u when am done.

[UPDATE] You got mail bro.
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 6:04am On Oct 17, 2010
Thanks. Got it and pretty happy with the result. Thanks for your help bro smiley.
Re: Site Review (security Analysis) - Gamecdswap by friendehis(m): 10:05am On Oct 18, 2010
Nice layout


Powerful graphics

Overall concept at the highest madness


Overall rating *****
Re: Site Review (security Analysis) - Gamecdswap by sayhi2ay(m): 2:58pm On Oct 18, 2010
- put successful registration details on the dashboard, and not the sidebar above the login info, that's not where users expect to find it

- on the welcome page: add 'Messages' quick link, and then the number of new messages , e.g Messages (3) or Messages *new

- You can have a functionality where users can click that they have interest in a game CD, but they might not have the exchange the original poster is looking for , then the poster can contact whoever is interested for alternate negotiations.

- Put the Recent available items available on another page entirely, not after the profile and account section. looks weird .

- i shouldn't be able to rate another user, unless we have had a transaction. you might need to implement another rating system though, people should be able to write a short note on feedback.

Well done!!! cool
Re: Site Review (security Analysis) - Gamecdswap by DualCore1: 5:34pm On Oct 18, 2010
Thanks guys,

Oga AY, thank god sey you no be the client sha. I for don mad by now. Thanks for your time to look into this for me. Don't go too far off the land just yet though, I am finishing up another site and would need reviews.

(1) (Reply)

Get An E-book On Step By Step Guide To Web Design/development / I Choose To Take A Bow / I Need A Theming Expert Now!

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 28
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.