Website Critiques
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsWeb DesignWebsite Critiques

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 19th, 2005, 07:03 PM
pjryan pjryan is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2005
Location: Bay Area
Posts: 28 pjryan User rank is Private First Class (20 - 50 Reputation Level)pjryan User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 7 h 16 m 9 sec
Reputation Power: 0
http://www.agavegroup.com

I'm interesting in getting a bit of feedback on a recent redesign of my personal site:

agavegroup.com.

I use the site as a my portfolio (this is the place of future development) as well as to write a handful of articles on ideas/projects (in blog format), and as a home to an informal forum.

I recently redesigned the site removing a lot of the blogged articles, and am have begun fresh new content.

The redesign involved using Wordpress as a CMS, and I am interested in any feedback about the design, navigation etc.

Thanks!

Reply With Quote
  #2  
Old August 19th, 2005, 07:26 PM
unseenweb unseenweb is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2005
Posts: 10 unseenweb User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 5 h 47 m 4 sec
Reputation Power: 0
Send a message via MSN to unseenweb Send a message via Yahoo to unseenweb
I love the rollover effect, it's really cool in the nav bar! And the onclick event aswell in the nav bar. Nice job, keep up the good work


Reply With Quote
  #3  
Old August 19th, 2005, 08:37 PM
Thr3ddy's Avatar
Thr3ddy Thr3ddy is offline
Harbinger of Harbingers
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jan 2004
Location: Coral Springs, Florida, USA
Posts: 926 Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)Thr3ddy User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 60916 Folding Title: Intermediate FolderFolding Points: 60916 Folding Title: Intermediate FolderFolding Points: 60916 Folding Title: Intermediate FolderFolding Points: 60916 Folding Title: Intermediate Folder
Time spent in forums: 2 Weeks 28 m 15 sec
Reputation Power: 377
Nice layout, yet you spelled development worng in About. : devlopment
__________________
Regards,
E. Luten.

Information: C, C++, STL, Boost, OpenMP, Scriptionary, Google
Book of the moment: Mastering Algorithms with C by Kyle Loudon
Interesting/Fun: CODE: The Hidden Language of Computer Hardware and Software by Charles Petzold
For Leisure: 1984 by George Orwell

Reply With Quote
  #4  
Old August 19th, 2005, 09:34 PM
pjryan pjryan is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2005
Location: Bay Area
Posts: 28 pjryan User rank is Private First Class (20 - 50 Reputation Level)pjryan User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 7 h 16 m 9 sec
Reputation Power: 0
Thank you! Somehow I missed that misspelling (and on the front page!). I've made the fix (having a CMS suddenly seems like it was a good idea...)

Reply With Quote
  #5  
Old August 19th, 2005, 09:46 PM
Memnoch1207 Memnoch1207 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 67 Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 19 h 10 m 47 sec
Reputation Power: 14
Your site isn't secure. I hacked it and already found the names of fields and tables in your database.


Need proof?

Table Name: wp_posts
Field Name: post_parent, post_status
__________________
Being educated does not make you intelligent

Reply With Quote
  #6  
Old August 20th, 2005, 12:48 AM
jinexile's Avatar
jinexile jinexile is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Location: Alberta Canada
Posts: 113 jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 23 h 46 sec
Reputation Power: 7
Send a message via ICQ to jinexile
How is that proof? All you need to do is look at the Wordpress source thats free for anyone to download.
__________________
I'm moving to Theory, everything works there.

Reply With Quote
  #7  
Old August 20th, 2005, 02:58 AM
Memnoch1207 Memnoch1207 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 67 Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 19 h 10 m 47 sec
Reputation Power: 14
You right...I didn't know what I was doing.

Reply With Quote
  #8  
Old August 20th, 2005, 11:39 AM
Sepodati's Avatar
Sepodati Sepodati is offline
Banned
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Dec 1999
Location: Afghanistan
Posts: 14,385 Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)  Folding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate Folder
Time spent in forums: 2 Months 4 Weeks 1 Day 56 m 51 sec
Reputation Power: 1873
Send a message via ICQ to Sepodati Send a message via Yahoo to Sepodati
Why are you using Yahoo sites to process your forms? Your "contact" form is insecure, to. You're not filtering the subject for newlines and that allows anyone to add headers and content to the messages your server sends out. I can use it to spam people, all from your site.

$subject = str_replace(array("\n","\r"),'', $subject);

Quote:
Originally Posted by Memnoch1207
You right...I didn't know what I was doing.
Well, at least you admit it. Honestly, what good is your "proof". If you found a vulnerability, report it with, hopefully, a fix. You don't have to post it here, but at least mention you emailed someone or something. Posting "I hacked you" is worthless.

---John Holmes...

Reply With Quote
  #9  
Old August 20th, 2005, 12:19 PM
Memnoch1207 Memnoch1207 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 67 Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 19 h 10 m 47 sec
Reputation Power: 14
Quote:
Originally Posted by Sepodati
Well, at least you admit it. Honestly, what good is your "proof". If you found a vulnerability, report it with, hopefully, a fix. You don't have to post it here, but at least mention you emailed someone or something. Posting "I hacked you" is worthless.

---John Holmes...

I point out vulnerabilities to people. If they want to contact me about how I did it, they can PM me. I'm not going to publicly post how I bypassed someones security, so some idiot can go do exactly what I did and steal or delete that person's information.

If people spent 1/2 as much time implementing security into their application, as they do pondering the look and feel of their site, then SQL Injection, XSS, Parmeter manipulation, etc... wouldn't continue to be a major problem.

You seem to be a major member of this board, so I would expect you to understand why a) I didn't explain how I attacked the site and b)why security is such an important issue that needs to be addressed.

Reply With Quote
  #10  
Old August 20th, 2005, 05:10 PM
jinexile's Avatar
jinexile jinexile is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Location: Alberta Canada
Posts: 113 jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level)jinexile User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 23 h 46 sec
Reputation Power: 7
Send a message via ICQ to jinexile
I never said you didn't do it, I said your proof wasn't proof. Hypothetically if I wanted to scare someone into giving me root access to their server I would use your tactic. I know they are using wordpress, so all I have to do is look through wordpress's database creation code to see what tables it creates and then tell the user I got it by hacking their site with no evidence to the sort. Then tell them I can fix it, just give me access. I may fix their problem but leave a backdoor for myself.

What sepodati does is show's them exactly how their site is insecure and how it can be exploited,that's proof.

Reply With Quote
  #11  
Old August 20th, 2005, 05:21 PM
Memnoch1207 Memnoch1207 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 67 Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level)Memnoch1207 User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 19 h 10 m 47 sec
Reputation Power: 14
Quote:
Originally Posted by jinexile
What sepodati does is show's them exactly how their site is insecure and how it can be exploited,that's proof.

I'll say it again...
Quote:
Originally Posted by memnoch1207
I point out vulnerabilities to people. If they want to contact me about how I did it, they can PM me. I'm not going to publicly post how I bypassed someones security.

Reply With Quote
  #12  
Old August 20th, 2005, 05:27 PM
Sepodati's Avatar
Sepodati Sepodati is offline
Banned
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Dec 1999
Location: Afghanistan
Posts: 14,385 Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)Sepodati User rank is General 13rd Grade (Above 100000 Reputation Level)  Folding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate FolderFolding Points: 76952 Folding Title: Intermediate Folder
Time spent in forums: 2 Months 4 Weeks 1 Day 56 m 51 sec
Reputation Power: 1873
Send a message via ICQ to Sepodati Send a message via Yahoo to Sepodati
Quote:
Originally Posted by Memnoch1207
I point out vulnerabilities to people. If they want to contact me about how I did it, they can PM me.
Then say that in your posts...

---John Holmes...

Reply With Quote
  #13  
Old August 22nd, 2005, 01:16 PM
pjryan pjryan is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2005
Location: Bay Area
Posts: 28 pjryan User rank is Private First Class (20 - 50 Reputation Level)pjryan User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 7 h 16 m 9 sec
Reputation Power: 0
Quote:
Originally Posted by Sepodati
...Your "contact" form is insecure, to. ...

$subject = str_replace(array("\n","\r"),'', $subject);


Thanks for this. I'll update soon. I greatly appreciate the detailed solution!


Quote:
Originally Posted by Memnoch1207
I point out vulnerabilities to people. If they want to contact me about how I did it, they can PM me. I'm not going to publicly post how I bypassed someones security.

Unfortunately I don't seem to be able to send PMs on this discussion board... Though I seem to be able to recieve them... I'd be iterested to hear what you did, would you mind sending me a PM with an email?

I'm a front-end guy (which isn't an excuse..) so I'm lacking expertise in security etc (in my contract work I operate with a "back-end" guy when necessary, but I didn't go down this path on my personal site). So all security discussions are very welcome.

PR
agavegroup

Reply With Quote
Reply

Viewing: Dev Shed ForumsWeb DesignWebsite Critiques > http://www.agavegroup.com


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Linear Mode Linear Mode