Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
To post in this sub-forum you must have made 100 posts or have Trust status or have completed our ID Verification



View this topic in a long page with up to 500 replies per page Create new topic
1 | ... | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | ... | 36
dontpanic42
1574 posts

Uber Geek
+1 received by user: 11


  #694794 2-Oct-2012 12:48
Send private message

gzt: Why would you? Try the forgot password link. Deleting cookies before that may help also if there are weird session issues, which there are.


Nope.
Forgot password link just re-directs to the now infamous 404 page.
Tried numerous different browsers, deleting cookies/cache etc.
Nothing works. Every time it just redirects to the 404 page.
Attempting to login with different browsers with all caches/cookies cleared exhibits the same outcome... the 404 page.

Seems like I'm just going to have to wait until Wheedle gets back to me about my issue, if they ever do.



networkn
Networkn
32873 posts

Uber Geek
+1 received by user: 15472

ID Verified
Trusted
Lifetime subscriber

  #694795 2-Oct-2012 12:49
Send private message

oxnsox:
BarTender: My personal favourite is:

https://www.wheedle.co.nz/

They can't even get their secure version of the site working... doesn't bode well.

The secure site page loads for me, and stays on the https site for the login page (other options take me to the standard site).  
Don't have a login (and no intention to get one yet) to proceed further.


Yup it's ok for me. 


l43a2
1784 posts

Uber Geek
+1 received by user: 591

ID Verified
Trusted

  #694796 2-Oct-2012 12:51
Send private message

for a new zealand site, its bloody slow.







skewt
752 posts

Ultimate Geek
+1 received by user: 215


  #694810 2-Oct-2012 13:01
Send private message

That edit price issue is pretty bad, they really need to take the site offline immediately and fix the issues

They are getting bad press now because of it,
http://www.3news.co.nz/New-auction-site-Wheedle-puts-passwords-at-risk/tabid/412/articleID/271202/Default.aspx

ajobbins
5053 posts

Uber Geek
+1 received by user: 1279

Trusted

  #694813 2-Oct-2012 13:12
Send private message

Aaaand it's offline again

'Wheedle is down for maintenance'




Twitter: ajobbins


ajobbins
5053 posts

Uber Geek
+1 received by user: 1279

Trusted

  #694814 2-Oct-2012 13:14
Send private message

Mauricio, if you manage to get in touch with them offer my services too.

I'd be happy to fly in for a 4-6 month contract gig to consult on security for them. I have a fair bit of experience in the subject from working for their competitor ;)




Twitter: ajobbins


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
mattwnz
20520 posts

Uber Geek
+1 received by user: 4798


  #694818 2-Oct-2012 13:17
Send private message

freitasm: I just saw on Twitter one can change prices of any auction by just visiting a crafted URL.?I am not posting the URL here.

On that note, here is a warning:

DO NOT POST WHEEDLE EXPLOITS HERE. ANYONE DOING SO WILL BE BANNED ON SIGHT, NO RECOURSE.

You can list something is broken (as I did above) but do not post explicit instructions.




It's been down for maintenance most of the day I think and still down, so perhaps they are fixing these problems. I just can't understand why they didn't have a soft launch to beta test it before spending all that money on advertising. They could have even submitted a beta test link here for people to test it before going live. Fail 101 I think on all fronts.

The other thing I think they need is a phone number. Trademe has one, and I believe many people do use it, despite it being user pays. If they had an 0800 number that could be their point of difference over trademe, by providing free phone support.

freitasm
BDFL - Memuneh
80661 posts

Uber Geek
+1 received by user: 41078

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #694819 2-Oct-2012 13:17
Send private message

Somehow I think they will ignore my offer. If they do contact me be sure I'd work with an A Team...




Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Nety
2584 posts

Uber Geek
+1 received by user: 5

Retired Mod
Trusted
Lifetime subscriber

  #694820 2-Oct-2012 13:20
Send private message

ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..







Media centre PC - Case Silverstone LC16M with 2 X 80mm AcoustiFan DustPROOF, MOBO Gigabyte MA785GT-UD3H, CPU AMD X2 240 under volted, RAM 4 Gig DDR3 1033, HDD 120Gig System/512Gig data, Tuners 2 X Hauppauge HVR-3000, 1 X HVR-2200, Video Palit GT 220, Sound Realtek 886A HD (onboard), Optical LiteOn DH-401S Blue-ray using TotalMedia Theatre Power Corsair VX Series, 450W ATX PSU OS Windows 7 x64

mcraenz
1140 posts

Uber Geek
+1 received by user: 222


  #694822 2-Oct-2012 13:26
Send private message

Not sure if this has been mentioned but they seem to have issues with host headers as well.

http://www.wheedle.co.nz - Works
http://wheedle.co.nz - 404









 

Help me build a better way of doing politics in Aotearoa New Zealand

 

 

 


ajobbins
5053 posts

Uber Geek
+1 received by user: 1279

Trusted

  #694825 2-Oct-2012 13:30
Send private message

Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.




Twitter: ajobbins


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
networkn
Networkn
32873 posts

Uber Geek
+1 received by user: 15472

ID Verified
Trusted
Lifetime subscriber

  #694832 2-Oct-2012 13:44
Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken. If I were them, I would be putting out a press release right about now saying sorry folks, the site wasn't ready and they are going to take some time to fix it.

Then call in some experts and aim to have a relaunch in a month - with a private beta maybe a week earlier with a group of tech savvy people (Maybe Geekzone).

Having worked for their competitor for several years, and working with site security, risk, fraud and other trust and safety issues as a core part of my role, it seems that they have a long way to go in this space.

As well as basic site security they need to consider their ability to be able to detect and respond to phishing, alias (shill) bidding (or other manipulation), fraudulent users/listings, overseas scammers and the list goes on.

There is a lot that goes on behind the scenes in that marketplace that end users never see - and it would be very hard for a new company to foresee what risks they are facing. I could add a lot of value if they want to engage me.


Agreed, it's time they took the site offline with an apology and deal with the issues properly. 


Tel69
Tel69
261 posts

Ultimate Geek
+1 received by user: 4

Trusted
Lifetime subscriber

  #694838 2-Oct-2012 13:55
Send private message

Nety:
ajobbins: Aaaand it's offline again

'Wheedle is down for maintenance'


And hopefully it stays that way until they resolve the now quite large list of security issues..


Well one thing is certain. Their maintenance page works fine.

That's been throughly tested over the last few days.

crackrdbycracku
1168 posts

Uber Geek
+1 received by user: 68


  #694839 2-Oct-2012 13:57
Send private message




Didn't anybody tell you I was a hacker?

sleemanj
1514 posts

Uber Geek
+1 received by user: 315


  #694841 2-Oct-2012 14:02
Send private message

ajobbins:
Nety: And hopefully it stays that way until they resolve the now quite large list of security issues..


Unfortunately I don't think there is a quick fix for some of the issues.

It sounds like their security model is fundamentally broken.



Agree.

I don't need to see their code to already know it's hopeless, the sort of issues we are all noting are fairly strong indicators that the people implementing this site did not think about... well anything except churning out code quickly.

The SQL injection potential, the storing of plaintext credentials in cookies, the ability to edit (prices of) other advertisements than your own, the absolute lack of performance (appropriate database indexes are likely non-existent is my guess here), the lack of any sort of testing, the pretty obvious server-farm-consistency and probably reverse proxy issues, the lack of caching headers where appropriate, the fact that it's design is "just like trademe"...

It all says "we shopped this out to the lowest price", and what they have got is a few programmers in a team who were told "just make it like this site", and they went in without any forethought, copying and pasting random stuff from their previous projects.  It's going to be hack-city (hack as in bodged togethor code, although the other meaning would equally apply!).

Fixing many of these problems, properly, is going to be real fundamental rewrite stuff I expect.

How much did they say they spent developing this, did I hear 10 million?  That can't be right, but if it is, hey Wheedle, I wouldn't normally work on this type of site, but you spot me a million bucks up-front and I'll redevelop the whole thing for you - it's got to be a good deal, right, hey, it's cheaper than your car!









---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


1 | ... | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | ... | 36
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.