Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
Buying anything on Amazon? Please use the Geekzone Amazon aff link.


View this topic in a long page with up to 500 replies per page Create new topic
1 | ... | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | ... | 36
1571 posts

Uber Geek
+1 received by user: 11

Subscriber

  Reply # 694794 2-Oct-2012 12:48 Send private message

gzt: Why would you? Try the forgot password link. Deleting cookies before that may help also if there are weird session issues, which there are.


Nope.
Forgot password link just re-directs to the now infamous 404 page.
Tried numerous different browsers, deleting cookies/cache etc.
Nothing works. Every time it just redirects to the 404 page.
Attempting to login with different browsers with all caches/cookies cleared exhibits the same outcome... the 404 page.

Seems like I'm just going to have to wait until Wheedle gets back to me about my issue, if they ever do.

7570 posts

Uber Geek
+1 received by user: 1000

Trusted
Subscriber

  Reply # 694795 2-Oct-2012 12:49 Send private message

oxnsox:
BarTender: My personal favourite is:

https://www.wheedle.co.nz/

They can't even get their secure version of the site working... doesn't bode well.

The secure site page loads for me, and stays on the https site for the login page (other options take me to the standard site).  
Don't have a login (and no intention to get one yet) to proceed further.


Yup it's ok for me. 


1211 posts

Uber Geek
+1 received by user: 265


  Reply # 694796 2-Oct-2012 12:51 Send private message

for a new zealand site, its bloody slow.





384 posts

Ultimate Geek
+1 received by user: 36


  Reply # 694810 2-Oct-2012 13:01 Send private message

That edit price issue is pretty bad, they really need to take the site offline immediately and fix the issues

They are getting bad press now because of it,
http://www.3news.co.nz/New-auction-site-Wheedle-puts-passwords-at-risk/tabid/412/articleID/271202/Default.aspx

Awesome
4077 posts

Uber Geek
+1 received by user: 643

Trusted
Subscriber

  Reply # 694813 2-Oct-2012 13:12 Send private message

Aaaand it's offline again

'Wheedle is down for maintenance'




Twitter: ajobbins

Awesome
4077 posts

Uber Geek
+1 received by user: 643

Trusted
Subscriber

  Reply # 694814 2-Oct-2012 13:14 Send private message

Mauricio, if you manage to get in touch with them offer my services too.

I'd be happy to fly in for a 4-6 month contract gig to consult on security for them. I have a fair bit of experience in the subject from working for their competitor ;)




Twitter: ajobbins

7598 posts

Uber Geek
+1 received by user: 432


  Reply # 694818 2-Oct-2012 13:17 Send private message

freitasm: I just saw on Twitter one can change prices of any auction by just visiting a crafted URL.?I am not posting the URL here.

On that note, here is a warning:

DO NOT POST WHEEDLE EXPLOITS HERE. ANYONE DOING SO WILL BE BANNED ON SIGHT, NO RECOURSE.

You can list something is broken (as I did above) but do not post explicit instructions.




It's been down for maintenance most of the day I think and still down, so perhaps they are fixing these problems. I just can't understand why they didn't have a soft launch to beta test it before spending all that money on advertising. They could have even submitted a beta test link here for people to test it before going live. Fail 101 I think on all fronts.

The other thing I think they need is a phone number. Trademe has one, and I believe many people do use it, despite it being user pays. If they had an 0800 number that could be their point of difference over trademe, by providing free phone support.

BDFL
50458 posts

Uber Geek
+1 received by user: 4856

Administrator
Trusted
Geekzone
Subscriber

  Reply # 694819 2-Oct-2012 13:17 Send private message

Somehow I think they will ignore my offer. If they do contact me be sure I'd work with an A Team...




2580 posts

Uber Geek
+1 received by user: 5

Mod Emeritus
Trusted
Subscriber

  Reply # 694820 2-Oct-2012 13:20 Send private message

ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..







Media centre PC - Case Silverstone LC16M with 2 X 80mm AcoustiFan DustPROOF, MOBO Gigabyte MA785GT-UD3H, CPU AMD X2 240 under volted, RAM 4 Gig DDR3 1033, HDD 120Gig System/512Gig data, Tuners 2 X Hauppauge HVR-3000, 1 X HVR-2200, Video Palit GT 220, Sound Realtek 886A HD (onboard), Optical LiteOn DH-401S Blue-ray using TotalMedia Theatre Power Corsair VX Series, 450W ATX PSU OS Windows 7 x64

826 posts

Ultimate Geek
+1 received by user: 99


  Reply # 694822 2-Oct-2012 13:26 Send private message

Not sure if this has been mentioned but they seem to have issues with host headers as well.

http://www.wheedle.co.nz - Works
http://wheedle.co.nz - 404






Awesome
4077 posts

Uber Geek
+1 received by user: 643

Trusted
Subscriber

  Reply # 694825 2-Oct-2012 13:30 Send private message

Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.




Twitter: ajobbins

7570 posts

Uber Geek
+1 received by user: 1000

Trusted
Subscriber

  Reply # 694832 2-Oct-2012 13:44 Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.


Agreed, it's time they took the site offline with an apology and deal with the issues properly. 


Tel69
214 posts

Master Geek
+1 received by user: 2

Trusted
Subscriber

  Reply # 694838 2-Oct-2012 13:55 Send private message

Nety:
ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..


Well one thing is certain. Their maintenance page works fine.

That's been throughly tested over the last few days.

1152 posts

Uber Geek
+1 received by user: 65


  Reply # 694839 2-Oct-2012 13:57 Send private message





Didn't anybody tell you I was a hacker?

1020 posts

Uber Geek
+1 received by user: 46


  Reply # 694841 2-Oct-2012 14:02 Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken.



Agree.

I don't need to see their code to already know it's hopeless, the sort of issues we are all noting are fairly strong indicators that the people implementing this site did not think about... well anything except churning out code quickly.

The SQL injection potential, the storing of plaintext credentials in cookies, the ability to edit (prices of) other advertisements than your own, the absolute lack of performance (appropriate database indexes are likely non-existent is my guess here), the lack of any sort of testing, the pretty obvious server-farm-consistency and probably reverse proxy issues, the lack of caching headers where appropriate, the fact that it's design is "just like trademe"...

It all says "we shopped this out to the lowest price", and what they have got is a few programmers in a team who were told "just make it like this site", and they went in without any forethought, copying and pasting random stuff from their previous projects.  It's going to be hack-city (hack as in bodged togethor code, although the other meaning would equally apply!).

Fixing many of these problems, properly, is going to be real fundamental rewrite stuff I expect.

How much did they say they spent developing this, did I hear 10 million?  That can't be right, but if it is, hey Wheedle, I wouldn't normally work on this type of site, but you spot me a million bucks up-front and I'll redevelop the whole thing for you - it's got to be a good deal, right, hey, it's cheaper than your car!









---
James Sleeman

My hobby - listing small amounts of interesting/useful hobby electronic components hardware and stuff on Trademe for cheap, all good geek stuff for the "maker" revolution ;-)

Tip for Trademe addicts: install an addon for your browser to get thumbs for all listings.

1 | ... | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | ... | 36
View this topic in a long page with up to 500 replies per page Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





Trending now »

Hot discussions in our forums right now:

Has Spark (Telecom) locked their iphone 6 ?
Created by anewguy2014, last reply by michaelmurfy on 17-Dec-2014 14:32 (25 replies)
Pages... 2


forgot how to unlock a car door
Created by joker97, last reply by joker97 on 19-Dec-2014 19:10 (49 replies)
Pages... 2 3 4


Police Camera Van Disguise
Created by Reanalyse, last reply by coffeebaron on 19-Dec-2014 21:45 (23 replies)
Pages... 2


In defence of cats
Created by Rikkitic, last reply by DarthKermit on 17-Dec-2014 15:40 (68 replies)
Pages... 3 4 5


Slaughter of Innocents
Created by networkn, last reply by networkn on 19-Dec-2014 17:46 (64 replies)
Pages... 3 4 5


Lightbox launches on PlayStation 4
Created by freitasm, last reply by sultanoswing on 19-Dec-2014 20:56 (39 replies)
Pages... 2 3


How is iParcel these days?
Created by peejayw, last reply by surfisup1000 on 18-Dec-2014 21:45 (19 replies)
Pages... 2


Spray Foam Insulation
Created by AACTech, last reply by timbosan on 19-Dec-2014 16:58 (36 replies)
Pages... 2 3



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.