Project Help Wanted
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherProject Help Wanted

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 20th, 2004, 09:52 PM
nicora nicora is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 40 nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 h 7 m 15 sec
Reputation Power: 8
beta testers

I have quickly developed a little blog/ photolog application for my family and friends to keep in touch/share photos. It will be on the domain nicora.net when it's done, but it's just on my development server for now. I have somewhat tested it to this point, but really need some of you guys to go in and tear it apart, let me know of any bugs glitches errors or just simply bad development on my part. One thing that won't work until I get it on my domain is whenever you click a username, it errors out - that will work once I'm finished.

PLEASE refrain from cuss words/inappropriate language/photos!!!! My family will be BETA testing this as well.

http://meidevelopment.meierinc.com//nn/index.cfm

Thanks in advance!

Reply With Quote
  #2  
Old August 20th, 2004, 10:28 PM
codergeek42's Avatar
codergeek42 codergeek42 is offline
[Insert clever comment here.]
Dev Shed God 2nd Plane (6000 - 6499 posts)
 
Join Date: Jul 2003
Location: Anaheim, CA (USA)
Posts: 6,435 codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)codergeek42 User rank is General 3rd Grade (Above 100000 Reputation Level)  Folding Points: 39542 Folding Title: Starter FolderFolding Points: 39542 Folding Title: Starter Folder
Time spent in forums: 1 Month 1 Week 6 Days 10 h 39 m 10 sec
Reputation Power: 1158
Send a message via ICQ to codergeek42 Send a message via AIM to codergeek42 Send a message via Yahoo to codergeek42 Send a message via Google Talk to codergeek42
Moved from the Lounge.
__________________
~~ Peter ~~
( My Blog: It's exactly like normal nerdiness, but completely different. ) :: ( Supporter of the EFF & FSF ) :: ( I'm a GNU/Linux addict and Free Software Advocate. ) :: ( How to Ask Questions the Smart Way ) :: ( The Fedora Project, sponsored by Red Hat ) :: ( GNOME: The Free Software Desktop Project ) :: ( GnuPG Public Key )

Reply With Quote
  #3  
Old August 20th, 2004, 10:30 PM
medialint's Avatar
medialint medialint is offline
Type Cast Exception
Click here for more information.
 
Join Date: Apr 2004
Location: West of Oakland, North of San Jose, South of Marin
Posts: 12,644 medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)  Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Months 3 Weeks 5 Days 4 h 18 m 2 sec
Reputation Power: 2808
Nice effort! I have a similar project but you're a lot further into it. Anyway, things I noticed:

I selected six .jpg files or so, it created the log but said "Only JPEG allowed"

Then I uploaded one renamed .jpeg

Didn't complain but didn't publish it.

Then I went and added three .jpg again. Took it, but didn't show up on my "my photologs" screen, only when I went to the main area and found my upload. Then it appeared there again (maybe a cache issue - explicit no-cache?).

I think you've done quite well.

Now the big test. I took a 3+MB mp3 file, named it .jpg. (my own song, btw, a demo for a free softsynth I did in synthedit).

It's taking it all which makes me wonder what would have happened if I picked a 400MB .wav ...

Well .. it gave me this:

Quote:
Error Occurred While Processing Request

Error Diagnostic Information

An error occurred while evaluating the expression:

evaluate(img_width*img_height) GT 307200

Error near line 23, column 41.

Cannot convert to number.

Please, check the ColdFusion manual for the allowed conversions between data types

The error occurred while processing an element with a general identifier of (CFIF), occupying document position (23:5) to (23:51) in the template file C:\INETPUB\WWWROOT\NN\\0.001\\PHOTOLOGS\\
ACT_PHOTOLOGS_UPDATEPHOTOLOG.CFM.

Date/Time: 08/20/04 20:29:27
Browser: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6) Gecko/20040113
Remote Address: xx.xxx.xxx.xxx
HTTP Referrer: http://meidevelopment.meierinc.com//nn//index.cfm?f=12010&photologsID=
DE6E26E5-67A6-4384-BA5F-C77E84D8B04B

Last edited by medialint : August 20th, 2004 at 10:32 PM. Reason: remove my IP from the error msg :)

Reply With Quote
  #4  
Old August 20th, 2004, 10:44 PM
nicora nicora is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 40 nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 h 7 m 15 sec
Reputation Power: 8
perfect test medialint!

yep, looks like i need a fail safe for uploads, just a try catch should work fine for now. plus i will use a shorter timeout on the lock so if your upload takes longer than say... 10 minutes, it will fail and send an error back to the user.

Thanks!!

Reply With Quote
  #5  
Old August 20th, 2004, 11:21 PM
medialint's Avatar
medialint medialint is offline
Type Cast Exception
Click here for more information.
 
Join Date: Apr 2004
Location: West of Oakland, North of San Jose, South of Marin
Posts: 12,644 medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)medialint User rank is General 27th Grade (Above 100000 Reputation Level)  Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1Folding Points: 246054 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Months 3 Weeks 5 Days 4 h 18 m 2 sec
Reputation Power: 2808
I think you should cut off the size, if it exceeds, say, 250KB or whatever limit you wish to set.

Reply With Quote
  #6  
Old August 25th, 2004, 10:57 PM
nicora nicora is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 40 nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 h 7 m 15 sec
Reputation Power: 8
i still really need some beta testers. if you have the time, please sign up for an account, then post some blog entries and upload some photo's to the photolog! Thx!!

http://64.185.116.132/nn/index.cfm

Reply With Quote
  #7  
Old August 28th, 2004, 02:21 PM
nicora nicora is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 40 nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 h 7 m 15 sec
Reputation Power: 8
ok, version 2 is ready... i could use a few more test subjects.

Reply With Quote
  #8  
Old August 28th, 2004, 02:40 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
just off the bat. dont let it tell where the directory is at. this can be used for further probing into systems(security issue since they now know the directory structure.)

Reply With Quote
  #9  
Old August 28th, 2004, 02:55 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
big email sent regarding security risk(high risk cat)

if you need help on how to fix it let me know.

Reply With Quote
  #10  
Old August 28th, 2004, 03:03 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
--------------------------------------------------------------------------------

Error Occurred While Processing Request
Error Diagnostic Information
ODBC Error Code = 22001 (String data right truncation)


[Microsoft][ODBC SQL Server Driver][SQL Server]String or binary data would be truncated.


SQL = "INSERT INTO photologs (photologsID, memberID, title, logUpdate, shared) VALUES ('12B8EA4A-DB49-4536-9B3D-1095597189B8', '067591B9-0609-48AB-B85E-05ED7A03EBFD', 'testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing testing ', {ts '2004-08-28 13:02:52'}, '1')"

Data Source = "NICORA_NET"


The error occurred while processing an element with a general identifier of (CFQUERY), occupying document position (42:4) to (42:39) in the template file C:\INETPUB\WWWROOT\NN\\0.001\\PHOTOLOGS\\ACT_PHOTOLOGS_ADDPHOTOLOG.CFM.


Date/Time: 08/28/04 13:02:52
Browser: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; sbcydsl 3.12; YPC 3.0.0; SV1; .NET CLR 1.0.3705)
Remote Address: 24.6.87.24
HTTP Referrer: http://meidevelopment.meierinc.com//nn/index.cfm?f=12010





--------------------------------------------------------------------------------

Reply With Quote
  #11  
Old August 28th, 2004, 03:04 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
this was for a VERY long file name for uploading. another high risk problem.

Reply With Quote
  #12  
Old August 28th, 2004, 03:12 PM
nicora nicora is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 40 nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level)nicora User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 3 h 7 m 15 sec
Reputation Power: 8
maxlengths have been applied to all text fields and i'm going through INSERT and UPDATE statements to trim field values so there aren't any truncation errors.

This is a great test and I appreciate the time VERY MUCH!

directory structure is showing up in errors now, but when launched there will be custom error handeling.

Reply With Quote
  #13  
Old August 28th, 2004, 03:44 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
and I hope you got my VERY long email log I sent to you. lemme know if you didnt or did. thnx

Reply With Quote
  #14  
Old August 28th, 2004, 03:49 PM
amcmillin amcmillin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 68 amcmillin User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 30 m 3 sec
Reputation Power: 5
now am I allowed to do actual vulnerability testing on this script*cross site scripting, buffer overflows, sql injection,etc..*? and will we for our time get a copy of this for free?

Reply With Quote