thewooleymammoth Posted October 11, 2007 Share Posted October 11, 2007 but it should be alright, tell me what you think! http://www.getyourlinkon.net ! thanks. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/ Share on other sites More sharing options...
jcombs_31 Posted October 11, 2007 Share Posted October 11, 2007 Looks pretty terrible. I really don't even know where to begin. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367018 Share on other sites More sharing options...
thedarkwinter Posted October 11, 2007 Share Posted October 11, 2007 yeah, its not very "appealing"... i cant tell what i does without registering... big put off!!! Â also, "responcible" is spelt "responsible", with an S Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367084 Share on other sites More sharing options...
thewooleymammoth Posted October 11, 2007 Author Share Posted October 11, 2007 i disagree. no offense but i think it fairly clear what the website does, and thanks for the spelling correction Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367215 Share on other sites More sharing options...
ingeva Posted October 11, 2007 Share Posted October 11, 2007 also, "responcible" is spelt "responsible", with an S Â In a phorum like thiz.... hoo carez? Â Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367222 Share on other sites More sharing options...
SharkBait Posted October 11, 2007 Share Posted October 11, 2007 What is it? Â Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367264 Share on other sites More sharing options...
moberemk Posted October 11, 2007 Share Posted October 11, 2007 Yes, it is clear. To you. But since you designed the site, then it really isn't something you can tell after a while. Well, in review: The design is thirty-second CSS and hideous, the GETYOURLINKON capitalization is freakishly annoying, it uses tables, and the front-page text is a hideous blob of clueless rambling with no clear purpose and no explanation of something basic like the point of the site. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367338 Share on other sites More sharing options...
thewooleymammoth Posted October 11, 2007 Author Share Posted October 11, 2007 i only used notepad to create this site, and i still think its fairly obvious what this site does, just as obvious as you tube or 4chan... and i agree about the front page of the site being pointless and such but that was written just to be an index page on the first day i started creating the site., i still have much cosmetic work to do on the site, i know. (waiting for photoshop to download). I was really more concerned about what people thought of the system, and how things worked in the site. but i guess all that matters is that i have tables? and the "front-page" (home or index) is annoying. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367385 Share on other sites More sharing options...
Adam Posted October 11, 2007 Share Posted October 11, 2007 Try not to use GETYOURLINKON.NET too much, it makes the text harder and longer to read... you can just use "we" or something. Â Btw this is the critique forum, for more system testing.. try the BETA testing forum. I had a quick look though and security seems alreyt! but im not an expert with the sql injections and that. All seems to run smooth enough, not keen on the like confirmed registration messages and that on a seperate page tho.. seems to take too long, best having them just appear on the homepage or the apropriate page or something. Â adam Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367403 Share on other sites More sharing options...
thewooleymammoth Posted October 11, 2007 Author Share Posted October 11, 2007 k thanks, thats the kinda stuff i was looking for, i have had people test for security, and i know my site isnt done yet, but i think im almost done (besides bugs and maybe a few features) with the overall system of how things work, just wanted to know what other people think. leave my cosmetics alone. and i changed the index page just for you guys! Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367406 Share on other sites More sharing options...
thewooleymammoth Posted October 11, 2007 Author Share Posted October 11, 2007 also, "responcible" is spelt "responsible", with an S Â In a phorum like thiz.... hoo carez? Â Â eczaktly Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367412 Share on other sites More sharing options...
Azu Posted October 11, 2007 Share Posted October 11, 2007 Ew the amount of sql injection vulnerability is outrageous. If I wanted to I could delete your whole database. And depending on the version of MySQL that you are running, I might even be able to arbitrarily delete/install/run any file on your computer in any drive I wish. Â Bad. Â Also, your Google adsense account will probally be shutdown soon for your blatant terms of service violation. Google is not leniant. Â In any case, your website is all around ugly, no offense, but it could use some colors or something. And putting the name of your website IN ALL CAPS EVERY SINGLE TIME YOU MENTION IT (WHICH IS ON EVERY PAGE) IS ANNOYING BECAUSE IT MAKES IT SEEM LIKE YOU ARE SHOUTING OR SOMETHING. Â Again, no offense, you just asked for an honest critique so I gave one. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367414 Share on other sites More sharing options...
AXiSS Posted October 11, 2007 Share Posted October 11, 2007 i only used notepad to create this site, and i still think its fairly obvious what this site does, just as obvious as you tube or 4chan... and i agree about the front page of the site being pointless and such but that was written just to be an index page on the first day i started creating the site., i still have much cosmetic work to do on the site, i know. (waiting for photoshop to download). I was really more concerned about what people thought of the system, and how things worked in the site. but i guess all that matters is that i have tables? and the "front-page" (home or index) is annoying. Err... it's content is about as obvious as the content of McDonald's Mystery Meat. And as long as you are referencing Youtube, you might get a clue about what aesthetic design is. And the problem isn't just the tables, it is the fact that there is a total lack of any intelligent design displayed on the site. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-367499 Share on other sites More sharing options...
thewooleymammoth Posted October 12, 2007 Author Share Posted October 12, 2007 photoshop is done... and now im done.... still working on small things but the cosmetics are done. what do you think now? Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368030 Share on other sites More sharing options...
moberemk Posted October 12, 2007 Share Posted October 12, 2007 It's worse now. You have some random cheesy graphic effects, no flow, and some pretty ugly graphics at that. There's no clear theme to the site whatsoever. Chains on the side, sparkles in the subtitle, glowing blue crossthatched something-or-others behind the initials... it just gets worse. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368057 Share on other sites More sharing options...
thewooleymammoth Posted October 12, 2007 Author Share Posted October 12, 2007 Ew the amount of sql injection vulnerability is outrageous. If I wanted to I could delete your whole database. And depending on the version of MySQL that you are running, I might even be able to arbitrarily delete/install/run any file on your computer in any drive I wish. Â Bad. Â Also, your Google adsense account will probally be shutdown soon for your blatant terms of service violation. Google is not leniant. Â In any case, your website is all around ugly, no offense, but it could use some colors or something. And putting the name of your website IN ALL CAPS EVERY SINGLE TIME YOU MENTION IT (WHICH IS ON EVERY PAGE) IS ANNOYING BECAUSE IT MAKES IT SEEM LIKE YOU ARE SHOUTING OR SOMETHING. Â Again, no offense, you just asked for an honest critique so I gave one. Â really? what code did you use to inject? Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368072 Share on other sites More sharing options...
Azu Posted October 12, 2007 Share Posted October 12, 2007 Sorry but I'm not going to post code on here that could be used as an attack vector. Â If you want help securing your site I could try to help you though. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368106 Share on other sites More sharing options...
thewooleymammoth Posted October 12, 2007 Author Share Posted October 12, 2007 sure, what do i need to do to block whatever injection you used? Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368110 Share on other sites More sharing options...
Azu Posted October 12, 2007 Share Posted October 12, 2007 Okay. If you're using the standard mysql library, then putting mysql_real_escape_string() around all of the input should sanatize pretty good unless you are using a very weird character set. Â So basically everywhere in your code that you use a $_GET or $_POST or $_SERVER you should surround that like so; mysql_real_escape_string($_POST['variable']) instead of just $_POST['variable']. Â Whatever code you are using against XSS (I'm guessing it's strip_tags?) apply that to the data AFTER it is retrieved from the database and about to be displayed, not before putting it into the database. mysqli_real_escape_string is for putting things INTO the database. Â Also it would probably be better if you just encoded the input as XSS protection instead of deleting all tags. That way if someone has a legit reason to post something with a <> in it it will display properly. Â To do this just replace the strip_tags with htmlspecialchars. Â Â If you are using the mysqli library then instead of mysql_real_escale_string use mysqli_real_escape_string and put the mysqli database link as the first parameter (E.G. mysql_real_escape_string($mysqli,$_POST['variable']) Â This should make it pretty secure as long as you aren't using a very weird encoding that is exploitable. If you're using something like UTF8 or ISO-something then you should be fine. Â Â Â So basically, all input should have mysql_real_escape_string before going into database, and htmlspecialchars when coming out of database. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368135 Share on other sites More sharing options...
thewooleymammoth Posted October 12, 2007 Author Share Posted October 12, 2007 Okay. If you're using the standard mysql library, then putting mysql_real_escape_string() around all of the input should sanatize pretty good unless you are using a very weird character set. Â So basically everywhere in your code that you use a $_GET or $_POST or $_SERVER you should surround that like so; mysql_real_escape_string($_POST['variable']) instead of just $_POST['variable']. Â Whatever code you are using against XSS (I'm guessing it's strip_tags?) apply that to the data AFTER it is retrieved from the database and about to be displayed, not before putting it into the database. mysqli_real_escape_string is for putting things INTO the database. Â Also it would probably be better if you just encoded the input as XSS protection instead of deleting all tags. That way if someone has a legit reason to post something with a <> in it it will display properly. Â To do this just replace the strip_tags with htmlspecialchars. Â Â If you are using the mysqli library then instead of mysql_real_escale_string use mysqli_real_escape_string and put the mysqli database link as the first parameter (E.G. mysql_real_escape_string($mysqli,$_POST['variable']) Â This should make it pretty secure as long as you aren't using a very weird encoding that is exploitable. If you're using something like UTF8 or ISO-something then you should be fine. Â Â Â So basically, all input should have mysql_real_escape_string before going into database, and htmlspecialchars when coming out of database. Â Â alright, next time i get some time to work on my site ill include that, i only need to include that on pages that connect to mysql dont i? Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368141 Share on other sites More sharing options...
Azu Posted October 13, 2007 Share Posted October 13, 2007 This only needs to be done for places where users input data that goes into the database. And for data being displayed from the database that was created by users. So yes, only pages that use the database. Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368347 Share on other sites More sharing options...
thewooleymammoth Posted October 13, 2007 Author Share Posted October 13, 2007 got it thanks ill do that for sure Quote Link to comment https://forums.phpfreaks.com/topic/72726-sites-up-may-still-be-some-minor-bugs/#findComment-368431 Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.