Click here to Skip to main content
15,886,519 members

The Weird and The Wonderful

   

The Weird and The Wonderful forum is a place to post Coding Horrors, Worst Practices, and the occasional flash of brilliance.

We all come across code that simply boggles the mind. Lazy kludges, embarrassing mistakes, horrid workarounds and developers just not quite getting it. And then somedays we come across - or write - the truly sublime.

Post your Best, your worst, and your most interesting. But please - no programming questions . This forum is purely for amusement and discussions on code snippets. All actual programming questions will be removed.

 
GeneralRe: Admin Scripts Pin
KbrKnight25-Aug-12 19:30
KbrKnight25-Aug-12 19:30 
GeneralAlcatraz ~ the tourist website PinPopular
0bx10-Aug-12 12:11
0bx10-Aug-12 12:11 
GeneralRe: Alcatraz ~ the tourist website Pin
R. Giskard Reventlov10-Aug-12 12:33
R. Giskard Reventlov10-Aug-12 12:33 
GeneralRe: Alcatraz ~ the tourist website Pin
Brisingr Aerowing10-Aug-12 14:13
professionalBrisingr Aerowing10-Aug-12 14:13 
JokeRe: Alcatraz ~ the tourist website Pin
krumia13-Aug-12 0:03
krumia13-Aug-12 0:03 
GeneralRe: Alcatraz ~ the tourist website Pin
Andrei Straut13-Aug-12 4:57
Andrei Straut13-Aug-12 4:57 
GeneralRe: Alcatraz ~ the tourist website Pin
BobJanova13-Aug-12 2:16
BobJanova13-Aug-12 2:16 
GeneralRe: Alcatraz ~ the tourist website PinPopular
enhzflep13-Aug-12 4:46
enhzflep13-Aug-12 4:46 
Big Grin | :-D That's gotta be the best laugh I've had all week. Since I was on a bender, thought I'd send this email to the company. Let their response time be a testament to how seriously they take security. Laugh | :laugh: Laugh | :laugh:

Gday Sir/Madam,

Have just read a forum post that lambastes your website for it's poor security. There are at least 2 problems with it as it stands

1) You've used a HTTP GET to pass variables to this page (the order number is present in the URL)
2) You've not authenticated the viewer as being the customer that placed the order.

For instance, I can enter the URL "https://www.alcatraztrips.com/Confirmation.asp?order=17900" and straight away see that Mary Cruz did attend the tour on 27 Sep 2005, leaving from Pier 33 at 11.15am


I can then enter the URL "https://www.alcatraztrips.com/Confirmation.asp?order=169000" and similarly I can see that Silvia Bollati is scheduled to attend a tour on the 25th August 2012 (13 days from now) Also departing pier 33, this time at 10am.


What if I or somebody else wanted to harm Silvia? Simple, run a program to harvest all the orders on your website, scan through them for the name of a purchaser of interest


It certainly doesn't take somebody that's particularly bright to understand that
(a) This is a massive security hole
(b) If somebody scheduled to attend the tour was located as a result of the service and subsequently murdered, your company would be held liable!!!

Kind of ironic for a website that deals in tours to a decommissioned Prison, don't you think?

You can view the lambasting here: http://www.codeproject.com/Messages/4335687/Alcatraz-the-tourist-website.aspx

Cheers,
Simon.

Make it work. Then do it better - Andrei Straut

GeneralRe: Alcatraz ~ the tourist website Pin
Andrei Straut13-Aug-12 4:59
Andrei Straut13-Aug-12 4:59 
GeneralRe: Alcatraz ~ the tourist website Pin
enhzflep13-Aug-12 5:14
enhzflep13-Aug-12 5:14 
GeneralRe: Alcatraz ~ the tourist website Pin
Andrei Straut13-Aug-12 5:51
Andrei Straut13-Aug-12 5:51 
JokeRe: Alcatraz ~ the tourist website Pin
AspDotNetDev13-Aug-12 5:50
protectorAspDotNetDev13-Aug-12 5:50 
GeneralRe: Alcatraz ~ the tourist website Pin
enhzflep13-Aug-12 6:12
enhzflep13-Aug-12 6:12 
GeneralRe: Alcatraz ~ the tourist website PinPopular
AspDotNetDev13-Aug-12 6:25
protectorAspDotNetDev13-Aug-12 6:25 
GeneralRe: Alcatraz ~ the tourist website Pin
enhzflep13-Aug-12 6:34
enhzflep13-Aug-12 6:34 
GeneralRe: Alcatraz ~ the tourist website Pin
Bernhard Hiller14-Aug-12 21:24
Bernhard Hiller14-Aug-12 21:24 
GeneralRe: Alcatraz ~ the tourist website Pin
Brisingr Aerowing15-Aug-12 15:03
professionalBrisingr Aerowing15-Aug-12 15:03 
GeneralConvertToReadableNumber PinPopular
Arpikusz8-Aug-12 21:57
Arpikusz8-Aug-12 21:57 
GeneralRe: ConvertToReadableNumber PinPopular
Shameel8-Aug-12 22:33
professionalShameel8-Aug-12 22:33 
GeneralRe: ConvertToReadableNumber PinPopular
J4amieC9-Aug-12 0:43
J4amieC9-Aug-12 0:43 
GeneralRe: ConvertToReadableNumber Pin
Brisingr Aerowing9-Aug-12 14:46
professionalBrisingr Aerowing9-Aug-12 14:46 
GeneralRe: ConvertToReadableNumber Pin
bojanh13-Aug-12 4:14
bojanh13-Aug-12 4:14 
GeneralRe: ConvertToReadableNumber Pin
Bernhard Hiller9-Aug-12 0:55
Bernhard Hiller9-Aug-12 0:55 
GeneralRe: ConvertToReadableNumber Pin
Eddy Vluggen9-Aug-12 1:06
professionalEddy Vluggen9-Aug-12 1:06 
GeneralRe: ConvertToReadableNumber Pin
Pete O'Hanlon9-Aug-12 1:47
mvePete O'Hanlon9-Aug-12 1:47 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.