Jump to content

Is this email being smart ass?

gibbsy81

A friend of my father has started a delivery company i checked out his website and found a number of security issues so i wrote the following email.

 

 

 

Hello [NAME OBSCURED}

I have noticed that you have created the site for your new delivery company there is just a few things that should be fixed/setup to make it a bit more secure.
Firstly the directory's xyztest and /xyztest/Vendors/ shouldn't really be publicly accessible this can be fixed.
Simply by creating a index.php file in those directory's and having the following code placed in them:
<?php
echo "<h1>Error 404 Not Found</h1>";
echo "The page that you have requested could not be found.";
?>

Secondly ssl should be forced site wide especially for things such as login data and personal information like phone numbers and addresses that would be transmitted via the drivers portal system.
I have noticed when navigating to https://[DOMAIN OBSCURED] cpanel throws an error and redirects the user to the defaultwebpage.cgi indicating that ssl has not been configured, and that the ssl certificate is self signed.
Really ssl should be forced site wide with a signed certificate.
 
Thirdly the wp-admin directory isn't hardened see this link about hardening the wp-admin directory http://codex.wordpress.org/Hardening_WordPress#Securing_wp-admin
 
Fourthly this is purely aesthetic but the site title has the stock Just another WordPress site.
 
Finally the social media buttons in the bottom right corner don't link to the pages eg Facebook goes to https://www.facebook.com/ when it probably should goto https://www.facebook.com[Facebook Page Obscured]
not really a security issue but just doesn't look professional.
Regards
Tomas Gibbs
 
Is this really being smart ass in my head i intended for it to be a more of a friendly thing to show him some issues with his site and show him how to fix them.
Link to comment
Share on other sites

Link to post
Share on other sites

Yes, you sound like you know everything.

Main Gaming PC (new): HP Omen 30L || i9 10850K || RTX 3070 || 512GB WD Blue NVME || 2TB HDD, 4TB HDD, 8TB HDD ||  750W P2 ||  16GB HyperX Black DDR4

Main Gaming PC (old, still own) : Intel Core i7 7700K @5.0Ghz || GPU: GTX 1080 Seahawk EK X || Motherboard: Maximus VIII Impact || Case: Fractal Design Define Nano S || RAM : 32GB Corsair Vengeance LPX 

Cooling: EK XRES D5 100mm || Alphacool ST30 280mm w/ Vardars || Alphacool ST30 240mm w/ Vardars || Swiftech 3/8 x 1/2'' Lok-Seal Compressions || Swiftech EVGA Hydrocopper Block || Primochill Advanced LRT Orange || Distilled Water

Folding@Home Rig: 2x X5690s @4.6Ghz || GPUs: 2x Radeon HD 7990 || Motherboard: EVGA SR-2 || Case: Corsair 900D || RAM: 48GB Corsair Dominator GT 2000Mhz CL9

Ethereum Mining Rig: Pentium G4400 || Gigabyte Z170X-UD5 TH || 2x GTX 1060s (Samsung & Hynix) 1x GTX 1070 (Micron), 2x RX480s BIOS modded (Samsung), 1x R9 290X 8GB, 1x GTX 1660 Super = ~ 195 Mh/s

Peripherals: 3x U2412M (5760x1200), 1x U3011 (2560x1600) || Logitech G710 (Cherry Blues) || Logitech G600 || Brainwavz HM5 with @Gofspar Mod 

Laptop: Dell XPS 15 || "Infinity Edge" 4K IPS Screen || i7 7700HQ || GTX 1050 || 16GB 2400Mhz RAM 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Yes it sounds quite douchey if you ask me

 

You could try saying things like "hey i know you made that site and congrats and all but if you want my help concerning some security issues i found on it i'm ready to help you"

Link to comment
Share on other sites

Link to post
Share on other sites

Yes, but I don't really see an issue with that.

Maybe add a disclaimer at the start? Something that says that you aren't trying to make an ass out of him, he may have just hired someone to make the site for him.

 

Spoiler

Case Bitfenix Ghost, Mobo Asus Maximus VIII Ranger, CPU i7 6700K @4.2 Ghz cooled by Arctic cooling Freezer i30, (barely). GPU Nvidia GTX 970 Gigabyte G1 @1519Mhz core, RAM 16Gb Crucial Ballistix CL16 @2400Mhz. SSD 128GB Sandisk Ultra Plus as my OS drive. HDD's  1TB  Seagate ST31000524AS its OEM, 3TB Seagate Barracuda, 2x 500GB WDC Blue (RAID 0)

If it isn't working absolutely perfectly, according to all your assumptions, it is broken.

Link to comment
Share on other sites

Link to post
Share on other sites

If he's getting paid for the website then he should fix it. I don't see a problem.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×