GetDotted Domains

Viewing Thread:
"Mess up my webshop please..."

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Wed 05/01/05 at 16:11
"Bothered!"
Posts: 207
Hi people, could you try and mess this up for me, its not on SSL yet but I will do that later...i want you people to test the security...thanks.

DO YOUR WORST...lol!

Cheers...SS

[URL]http://81.178.216.126/shop[/URL]

PS (Check this thread in case my IP changes)

SERVER GOES DOWN AT - 12:00 am
SERVER COMES ONLINE AT - 7:00 am
Thu 06/01/05 at 20:03
"Bothered!"
Posts: 207
Ok thanks...il look into that...validation. If you can do damage...do it my friend!
Thu 06/01/05 at 19:04
Regular
"Devil in disguise"
Posts: 3,151
An excellent start to making sure its secure would be validate all POST and GET data and handle it properly if its not.

Small example;
http://81.178.216.126/shop/show_cart.php?new=SCREWTHINGSUP

I've just put in random text there but if I was feeling malicious that would be one starting point to start to try to inject my own prices and so on. That URL at present gives me a blank item in the shopping cart. :)
Various other stuff like that in the site too, eg I currently have an item in my shopping cart with a quantity of b. :P
Thu 06/01/05 at 18:41
"Bothered!"
Posts: 207
OOO Turbonutter is back...can you have a go at this please...I want my security seriously tested.

Thanks.
Wed 05/01/05 at 19:43
"Bothered!"
Posts: 207
Right, another problem that I am faced with, is with MySQL 4, the expression LIKE %SOMETHING% worked so that it would return anything that contained the "SOMETHING" between the %'s. Since I upgraded the version of MySQL on the server, it hasn't worked. I'm referring to the page:

[URL]http://81.178.216.126/index.php?page=1&from=0&limit=10[/URL]

Enter something like "novafold" into the product description box, and hit ...see the problem.

Also, anyone else who wants to try and mess up the shop, feel free.
Wed 05/01/05 at 17:54
"Bothered!"
Posts: 207
Ok will do, thanks a lot.
Wed 05/01/05 at 17:52
Moderator
"Are you sure?"
Posts: 5,000
secret_squirrel™ wrote:
> Ok I see...sorry. They will be manually keying them in to their own
> terminal I think. I'll cross that bridge when i come to i
> think...but good point. Probably the keying into terminal method.

I've found this is the biggest hurdle to cross.

If they are proccessing offline (keying the transactions) then as long as your shop works for 'normal' visitors there will be no problem. If an order for 1000 thingies comes through for 2p they will see the carts been hacked and won't process the order.
I've got some shops that work like this (taking the order under a Thawte SSL and processing offline) and it all works fine. The problem comes with some banks 'Internet Merchant Accounts' that don't allow this - and insist on you using a PSP which gets more complicated and expensive.

Hope this makes sense!? Before you spend alot of time getting things up and running ensure their bank are happy...

Good Luck.
Wed 05/01/05 at 17:42
"Bothered!"
Posts: 207
Ok I see...sorry. They will be manually keying them in to their own terminal I think. I'll cross that bridge when i come to i think...but good point. Probably the keying into terminal method.
Wed 05/01/05 at 17:39
Moderator
"Are you sure?"
Posts: 5,000
secret_squirrel™ wrote:
> Payments will be made using the online webshop once I set up an SSL
> server. Key Catering then have their own credit card system.

Not sure what you mean by this. Will they be processing the payments manually by keying them into their own terminal or will the payments go automatically via a PSP (Payment Service Provider)?

There's a big difference in security...
Wed 05/01/05 at 17:34
"Bothered!"
Posts: 207
Lol, good good. I will watch in amazement...
Wed 05/01/05 at 17:32
Regular
"NULL"
Posts: 1,384
Just about to try and have some fun with Brutus.

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Thanks!
Thank you for dealing with this so promptly it's nice having a service provider that offers a good service, rare to find nowadays.
I've been with Freeola for 14 years...
I've been with Freeola for 14 years now, and in that time you have proven time and time again to be a top-ranking internet service provider and unbeatable hosting service. Thank you.
Anthony

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.