Website Critiques
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsWeb DesignWebsite Critiques

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 26th, 2003, 03:07 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 5
http://cars.betachat.com

Okay boys, and girls.. A new design needs a security check, and loop holes.

http://cars.betachat.com

The site holds information of a business of mine that contains cars bought, and sold.

Login with this information..

UserName: DevShed Users
Password: access



Have fun, and let me know what needs to be covered up, and what I've done wrong, and even what you would do if you were me. Don't be shy, let me have it!

EDIT:
The known bugs are:


1) In buyer_edit.php I can edit a buyer who doesn't exist by typing in buyer_edit.php?id=none_existant_buyer_number
for example "buyer_edit.php?id=5"
__________________
"I haven't failed, I've found 10,000 ways that won't work."
- Thomas Edison

-=Rick=-

Chat Refinance Loans

Last edited by URSLOWR : August 27th, 2003 at 09:31 AM.

Reply With Quote
  #2  
Old August 26th, 2003, 03:11 PM
karsh44's Avatar
karsh44 karsh44 is offline
Just another guy
Dev Shed Frequenter (2500 - 2999 posts)
 
Join Date: Jun 2003
Location: Wisconsin
Posts: 2,915 karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level)karsh44 User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 1 Week 6 Days 13 h 4 m 10 sec
Reputation Power: 75
Read the sticky. Next time put the web address in your topic. (And at least have the address somewhere in the post. We need to know where to go, after all.

Reply With Quote
  #3  
Old August 26th, 2003, 03:14 PM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 5
Whoops, I hate it when I forget to do things..

Reply With Quote
  #4  
Old August 27th, 2003, 01:40 AM
lisajill lisajill is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2003
Posts: 152 lisajill User rank is Private First Class (20 - 50 Reputation Level)lisajill User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 5
Send a message via ICQ to lisajill Send a message via AIM to lisajill Send a message via Yahoo to lisajill
i'm really tired so this'll be short but

search goes to a drop down for search... thats redundant, if a menu has only 1 option it should go there instantly via click... having to do it twice is annoying for the user

how do you get back to the first screen after login, once you've clicked an option? hehe i couldn't find it, should make that more obvious

payment > add payment only brings you to a list, i couldn't see a way to add a new one, should have list payments and add payment?


actually all the adds are doing that, is that just not imp'd yet?

other than that its good, sleek interface..

oh one other thing i noticed - from a data entry background, in add vehicle when you tab from version to date bought it tabs to submit, then tabs to the calender, then tabs to date bought the calender, it should tab to the date bought entry field; it should tab immediately to date bought, tabs should always be in sequence with extra buttons ignored, for fast data entry purposes

i like the layout tho, its very clean.. if this is going to be used for mass data entry you should attempt to make keyboard shortcuts for the menus, altho i dunno if you can, thas way beyond my scope

g'night!

one last thing, i was closing all my browsers and ihad a ton from you, i realized why - i thought that the 'view customer info' link didn't work, as it turned out, it opened up a new browser window.. that should open in the same window

really g'night now!
Comments on this post
JimmyGosling agrees!
__________________
Lisa
distant, early morning

Last edited by lisajill : August 27th, 2003 at 01:48 AM.

Reply With Quote
  #5  
Old August 27th, 2003, 05:55 AM
ishnid's Avatar
ishnid ishnid is offline
kill 9, $$;
Dev Shed God (5000 - 5499 posts)
 
Join Date: Sep 2001
Location: Dublin, Eire
Posts: 5,394 ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level)ishnid User rank is General 4th Grade (Above 100000 Reputation Level) 
Time spent in forums: 3 Months 5 Days 14 h 2 m 47 sec
Reputation Power: 1259
Overall . . . very nice with good interface.

Just a couple of small things (using IE5).

On the menu bar, clicking on the menu heading (Vehicle, Buyer etc.) when its submenu is expanded brings you back to the login page. It really should collapse the menu again. Also, when a menu is expanded, clicking in the main part of the page gives a javascript error:
Code:
Line: 408
Char: 7
Error: Object doesn't support this property or method
Code: 0
URL: http://cars.betachat.com/vehicle_display.php


On the main page (late.php after login), most of the text is black on dark blue background and is very hard to read. Either change text to white of lighten the background. Also, I can play around with the MySessID param in the url (including deleting it) without changing anything. Perhaps this isn't important.

Reply With Quote
  #6  
Old August 27th, 2003, 08:56 AM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 5
First, I'd like to say thanks for taking the time to look the site over.

Quote:
Originally posted by lisajill
i'm really tired so this'll be short but

search goes to a drop down for search... thats redundant, if a menu has only 1 option it should go there instantly via click... having to do it twice is annoying for the user..
-=Fixed=- Good catch, I was going to fix that, but just had not taken the time to do so since I *just* got done with the search option.


how do you get back to the first screen after login, once you've clicked an option? hehe i couldn't find it, should make that more obvious
-=Fixed=- I missed that one too. That is if you were talking about the late.php page?


payment > add payment only brings you to a list, i couldn't see a way to add a new one, should have list payments and add payment?
This one is tricky because I have to have a value in buyer_payment.php?id=vehicle_id Right now I can't think of any other way of doing this, any suggestions?

/\
|
actually all the adds are doing that, is that just not imp'd yet?

other than that its good, sleek interface..

oh one other thing i noticed - from a data entry background, in add vehicle when you tab from version to date bought it tabs to submit, then tabs to the calender, then tabs to date bought the calender, it should tab to the date bought entry field; it should tab immediately to date bought, tabs should always be in sequence with extra buttons ignored, for fast data entry purposes
I took a look at this and not sure what you mean. When I tabbed down the list, it went from...
Year->Make->Model->Version->DateBought(which is a read only input tag)->DateBoughtCalendarIcon->AmountBought->Submit
... I have the Date Bought input read only because *I* want to have the correct date format entered in, the only way I could do that is to have a pop-up calendar, that way the date is always in the format of mm/dd/yyyy, no matter who enters the data in. The reason for the formatting is basically for the "late.php" page.



i like the layout tho, its very clean.. if this is going to be used for mass data entry you should attempt to make keyboard shortcuts for the menus, altho i dunno if you can, thas way beyond my scope
It will be for mass entries, but only over a long period of time. Very long.

g'night!

one last thing, i was closing all my browsers and ihad a ton from you, i realized why - i thought that the 'view customer info' link didn't work, as it turned out, it opened up a new browser window.. that should open in the same window
That window is supposed to open on "target=top", so you should have seen them right away. But I got away from that and went right to the page without a pop-up.

really g'night now!


Once again, thanks for taking the time to check it out.

Last edited by URSLOWR : August 27th, 2003 at 08:59 AM.

Reply With Quote
  #7  
Old August 27th, 2003, 09:20 AM
URSLOWR URSLOWR is offline
<? unset($sanity) ?>
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jul 2003
Posts: 613 URSLOWR User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 1 m 38 sec
Reputation Power: 5
Quote:
Originally posted by ishnid
Overall . . . very nice with good interface.
Thanks!

Just a couple of small things (using IE5).

On the menu bar, clicking on the menu heading (Vehicle, Buyer etc.) when its submenu is expanded brings you back to the login page. It really should collapse the menu again. Also, when a menu is expanded, clicking in the main part of the page gives a javascript error:
Code:
Line: 408
Char: 7
Error: Object doesn't support this property or method
Code: 0
URL: http://cars.betachat.com/vehicle_display.php

I can solve this easily, because it's going to be only a selected crowd using this database. I'll just have them use the current version of IE. Also, the best resolution to view the site is 1024 by 768 (that's the res I used when making the layout).

On the main page (late.php after login), most of the text is black on dark blue background and is very hard to read. Either change text to white of lighten the background.
I'll look into lightening up the dark blue background.

Also, I can play around with the MySessID param in the url (including deleting it) without changing anything. Perhaps this isn't important.
I'm not sure if that's a threat of any kind, or if it will harm anything. I'll look it up and see what kind of problems it would cause. Other then that, I don't think it will have any effect on login access, unless someone was to know the MySessID and username and password. Only a select group will have access to this.


Thanks for taking your time to look this over.

Reply With Quote
Reply

Viewing: Dev Shed ForumsWeb DesignWebsite Critiques > Newly (almost) completed site needs testing!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!
 
Accelerating Trading Partner Performance
One in five. That's how many partner transactions have at least one error. That is an amazing statistic, particularly given the extraordinary leaps in innovation across the global supply chain during the past two decades. Download this white paper to learn more.

 
Competing on Analytics
This Tech Analysis is designed to help identify characteristics shared by analytics competitors, and includes information about 32 organizations that have made a commitment to quantitative, fact-based analysis.

 
Cost Effective Scaling with Virtualization and Coyote Point Systems
An overview of the industry trend toward virtualization, how server consolidation has increased the importance of application uptime and the steps being taken to integrate load balancing technology with virtualized servers.

 
Five Checkpoints to Implementing IP Telephony
Implementation planning for IP PBX software and IP telephony has become vital as businesses replace discontinued legacy PBX phone systems. This informative whitepaper outlines five "checkpoints" for any implementation plan that will help make IP communications a successful proposition.

 
Hosted Email Security: Staying Ahead of New Threats
In the last two years, email has become a fierce battleground between the nefarious forces of spam and malware, and the heroes of messaging protection. The spam volumes increased alarmingly every month, bringing clever new forms of phishing and virus propagation attacks.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway