Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

View this topic in a long page with up to 500 replies per page Create new topic
1 | ... | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | ... | 36
1571 posts

Uber Geek
+1 received by user: 11

Subscriber

  Reply # 694794 2-Oct-2012 12:48 Send private message

gzt: Why would you? Try the forgot password link. Deleting cookies before that may help also if there are weird session issues, which there are.


Nope.
Forgot password link just re-directs to the now infamous 404 page.
Tried numerous different browsers, deleting cookies/cache etc.
Nothing works. Every time it just redirects to the 404 page.
Attempting to login with different browsers with all caches/cookies cleared exhibits the same outcome... the 404 page.

Seems like I'm just going to have to wait until Wheedle gets back to me about my issue, if they ever do.

7124 posts

Uber Geek
+1 received by user: 840

Trusted
Subscriber

  Reply # 694795 2-Oct-2012 12:49 Send private message

oxnsox:
BarTender: My personal favourite is:

https://www.wheedle.co.nz/

They can't even get their secure version of the site working... doesn't bode well.

The secure site page loads for me, and stays on the https site for the login page (other options take me to the standard site).  
Don't have a login (and no intention to get one yet) to proceed further.


Yup it's ok for me. 


1184 posts

Uber Geek
+1 received by user: 245


  Reply # 694796 2-Oct-2012 12:51 Send private message

for a new zealand site, its bloody slow.





382 posts

Ultimate Geek
+1 received by user: 35


  Reply # 694810 2-Oct-2012 13:01 Send private message

That edit price issue is pretty bad, they really need to take the site offline immediately and fix the issues

They are getting bad press now because of it,
http://www.3news.co.nz/New-auction-site-Wheedle-puts-passwords-at-risk/tabid/412/articleID/271202/Default.aspx

Awesome
3968 posts

Uber Geek
+1 received by user: 562

Trusted
Subscriber

  Reply # 694813 2-Oct-2012 13:12 Send private message

Aaaand it's offline again

'Wheedle is down for maintenance'




Twitter: ajobbins

Awesome
3968 posts

Uber Geek
+1 received by user: 562

Trusted
Subscriber

  Reply # 694814 2-Oct-2012 13:14 Send private message

Mauricio, if you manage to get in touch with them offer my services too.

I'd be happy to fly in for a 4-6 month contract gig to consult on security for them. I have a fair bit of experience in the subject from working for their competitor ;)




Twitter: ajobbins

7240 posts

Uber Geek
+1 received by user: 403


  Reply # 694818 2-Oct-2012 13:17 Send private message

freitasm: I just saw on Twitter one can change prices of any auction by just visiting a crafted URL.?I am not posting the URL here.

On that note, here is a warning:

DO NOT POST WHEEDLE EXPLOITS HERE. ANYONE DOING SO WILL BE BANNED ON SIGHT, NO RECOURSE.

You can list something is broken (as I did above) but do not post explicit instructions.




It's been down for maintenance most of the day I think and still down, so perhaps they are fixing these problems. I just can't understand why they didn't have a soft launch to beta test it before spending all that money on advertising. They could have even submitted a beta test link here for people to test it before going live. Fail 101 I think on all fronts.

The other thing I think they need is a phone number. Trademe has one, and I believe many people do use it, despite it being user pays. If they had an 0800 number that could be their point of difference over trademe, by providing free phone support.

BDFL
49736 posts

Uber Geek
+1 received by user: 4521

Administrator
Trusted
Geekzone
Subscriber

  Reply # 694819 2-Oct-2012 13:17 Send private message

Somehow I think they will ignore my offer. If they do contact me be sure I'd work with an A Team...




2578 posts

Uber Geek
+1 received by user: 3

Mod Emeritus
Trusted
Subscriber

  Reply # 694820 2-Oct-2012 13:20 Send private message

ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..







Media centre PC - Case Silverstone LC16M with 2 X 80mm AcoustiFan DustPROOF, MOBO Gigabyte MA785GT-UD3H, CPU AMD X2 240 under volted, RAM 4 Gig DDR3 1033, HDD 120Gig System/512Gig data, Tuners 2 X Hauppauge HVR-3000, 1 X HVR-2200, Video Palit GT 220, Sound Realtek 886A HD (onboard), Optical LiteOn DH-401S Blue-ray using TotalMedia Theatre Power Corsair VX Series, 450W ATX PSU OS Windows 7 x64

820 posts

Ultimate Geek
+1 received by user: 95


  Reply # 694822 2-Oct-2012 13:26 Send private message

Not sure if this has been mentioned but they seem to have issues with host headers as well.

http://www.wheedle.co.nz - Works
http://wheedle.co.nz - 404






Awesome
3968 posts

Uber Geek
+1 received by user: 562

Trusted
Subscriber

  Reply # 694825 2-Oct-2012 13:30 Send private message

Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.




Twitter: ajobbins

7124 posts

Uber Geek
+1 received by user: 840

Trusted
Subscriber

  Reply # 694832 2-Oct-2012 13:44 Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.


Agreed, it's time they took the site offline with an apology and deal with the issues properly. 


Tel69
208 posts

Master Geek
+1 received by user: 2

Trusted
Subscriber

  Reply # 694838 2-Oct-2012 13:55 Send private message

Nety:
ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..


Well one thing is certain. Their maintenance page works fine.

That's been throughly tested over the last few days.

1152 posts

Uber Geek
+1 received by user: 64


  Reply # 694839 2-Oct-2012 13:57 Send private message





Didn't anybody tell you I was a hacker?

1006 posts

Uber Geek
+1 received by user: 42


  Reply # 694841 2-Oct-2012 14:02 Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken.



Agree.

I don't need to see their code to already know it's hopeless, the sort of issues we are all noting are fairly strong indicators that the people implementing this site did not think about... well anything except churning out code quickly.

The SQL injection potential, the storing of plaintext credentials in cookies, the ability to edit (prices of) other advertisements than your own, the absolute lack of performance (appropriate database indexes are likely non-existent is my guess here), the lack of any sort of testing, the pretty obvious server-farm-consistency and probably reverse proxy issues, the lack of caching headers where appropriate, the fact that it's design is "just like trademe"...

It all says "we shopped this out to the lowest price", and what they have got is a few programmers in a team who were told "just make it like this site", and they went in without any forethought, copying and pasting random stuff from their previous projects.  It's going to be hack-city (hack as in bodged togethor code, although the other meaning would equally apply!).

Fixing many of these problems, properly, is going to be real fundamental rewrite stuff I expect.

How much did they say they spent developing this, did I hear 10 million?  That can't be right, but if it is, hey Wheedle, I wouldn't normally work on this type of site, but you spot me a million bucks up-front and I'll redevelop the whole thing for you - it's got to be a good deal, right, hey, it's cheaper than your car!









---
James Sleeman

My hobby - listing small amounts of interesting/useful hobby electronic components hardware and stuff on Trademe for cheap, all good geek stuff for the "maker" revolution ;-)

Tip for Trademe addicts: install an addon for your browser to get thumbs for all listings.

1 | ... | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | ... | 36
View this topic in a long page with up to 500 replies per page Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Windows 10 announced, as well as developer preview
Created by macuser, last reply by Regs on 1-Oct-2014 22:24 (48 replies)
Pages... 2 3 4


Moment of Truth?
Created by BarTender, last reply by JimmyC on 29-Sep-2014 09:16 (441 replies)
Pages... 28 29 30


Can i have 2 ISP's at home?
Created by ReckITT, last reply by Lazarui on 30-Sep-2014 18:15 (49 replies)
Pages... 2 3 4


Why is your nickname what it is, what are the origins of it?
Created by Presso, last reply by hsvhel on 1-Oct-2014 11:52 (89 replies)
Pages... 4 5 6


What time will the Apple Store online be selling the iPhone 6?
Created by scotiwis, last reply by thewanderingv on 1-Oct-2014 22:49 (110 replies)
Pages... 6 7 8


iPhone 6 From Spark - Order Dates and Pricing?
Created by Otagolad, last reply by mahdibassam on 1-Oct-2014 17:03 (348 replies)
Pages... 22 23 24


Easiest way to have iPhone warranty service
Created by JoshWright, last reply by nitrotech on 30-Sep-2014 21:37 (15 replies)

Passwords and pesky teenagers
Created by martyyn, last reply by raytaylor on 1-Oct-2014 23:34 (27 replies)
Pages... 2



Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.