P.Z. Low Cost CPanel Web Hosting  

Go Back   P.Z. Low Cost CPanel Web Hosting > Page-Zone Web Hosting Main Forum > General FAQ > General Questions and Comments

General Questions and Comments Post your question or grace us with your knowledge. Posting limited to registered members.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Accepting credit card payments
Old
  (#1 (permalink))
loughderg
Registered User
loughderg is on a distinguished road
 
Status: Offline
Posts: 2
Join Date: Jan 2005
Rep Power: 0
Accepting credit card payments - 04-14-2005, 06:03 AM

Hi everyone,

I'm setting up a website for a friend who wants to be able to accept credit card payments online. This is to be hosted at p-z.

Rather than process the payments automatically, he wants the credit card details to be sent to an email address of his choosing. He then wants to be able to take the card details from the email and process the payment manually through the office card terminal.

I'd appreciate some advice on how to make the process as secure as possible (bearing in mind he's on a tight budget).

I've ordered a dedicated IP address to obtain a SSL cert, but appreciate that this will only encrypt the data from the browser to the server. The form data from the website is currently set up to be sent to an email address using a simple php script.

I'd appreciate some help with the following:

1. What pages do I need to make secure, i.e. do the form, submission confirmation and php script pages all need to be https?
2. Is the php script I have in place (web4future's Easiest Form2Mail) sufficiently secure for the taks of processing the submitted form, or should I be using something better?
3. What safeguards should I put in place at server level to make sure the data held there remains secure.
4. What is the best (and cheapest) way for my friend to retrieve the credit card data from the e-mail server?

You can probably guess from the above basic questions that I'm a novice at this whole thing, so I'd appreciate it if you could use basic layman's terms in your replies (so no parsing, arrays or parameters thanks )

I'd greatly appreciate any advice you may be able to give.

Many thanks,

William
   
Reply With Quote
Old
  (#2 (permalink))
midwest
blink and it's over
midwest will become famous soon enough
 
midwest's Avatar
 
Status: Offline
Posts: 803
Join Date: Oct 2002
Location: Big Sky, MT
Rep Power: 76
04-21-2005, 12:52 AM

I see that you have not recieved an answer so I'll give it a shot.

1. My preference is to do the whole site https

2. cant say for sure if it is secure...but at the least you should rename it so it does not have "mail" in the name. If there is a hole you can be sure that it(form2mail) will become a hot search term.

3. If I was to store CC#'s I would encrypt them with DES. Dont forget to validate with the Luhn formula(mod 10) first. You should also consider encrypting ~all~ customer data.

4. With an email client, driving to the server everyday would get bothersome
I would encrypt it with pgp or similar, this however may be beyond you and your client. No offense intended but it is not the easiest thing to do if unfamiliar with it. The best alternative is to split the CC# in two parts and send each part in a different email. For added security with this method you may wish to send each part to a different email address. Do not use IMAP-do not leave the mail on the server.

You say you are not experienced, this is not the thing to gain experience on, the repercussions are enormous. Hire it out or buy a canned solution. Just MHO.

a note of caution: unless your client has a very good (personal) relation with their bank it might be better to obtain a seperate merchant account for the online activity. That way if problems develop or they get slammed with too amny chargebacks they do not loose their brick&morter merchant account too.

HTH


Ronnie Gauthier
www.instaguide.com

======================
for official page-zone support please visit
www.page-zone.com/support.shtml
   
Reply With Quote
a hearty "second" to Ronnie's advice
Old
  (#3 (permalink))
stratplan
Registered User
stratplan will become famous soon enough
 
stratplan's Avatar
 
Status: Offline
Posts: 706
Join Date: Sep 2002
Location: Texas, USA
Rep Power: 72
a hearty "second" to Ronnie's advice - 04-21-2005, 06:38 AM

In these days of rampant Identity Theft, phishing, and other financial criminal activities, you (and your client) would best be served with a professional application.

It's been my experience that banks are not enthusiastic about on-line credit card entries and transactions where the card is not presented/swiped. They will charge out the kazoo for the account setup and then punish the account holder for any chargebacks. I would go the route of a third-party collector - a google search will turn up quite a few.

Bottom line: If you don't like swimming with sharks, don't go in this pond unprotected.


stratplan
Click Here to Visit Page-Zone's Help Desk
Help find disease cures: FoldForCures
   
Reply With Quote
Old
  (#4 (permalink))
loughderg
Registered User
loughderg is on a distinguished road
 
Status: Offline
Posts: 2
Join Date: Jan 2005
Rep Power: 0
04-22-2005, 09:09 AM

Thanks for both of your replies.

I've discussed the security issue further with my friend and I think I've talked him round to using a 3rd party as stratplan suggested.

Best regards,

William
   
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
WebCards e-card Script Jim Misc free php scripts 0 07-22-2007 12:28 PM
Accepting Online Payment Jim Tips 3 07-08-2006 12:59 PM
Credit Card Info thru email edwurster Off Topic Discussion 3 04-21-2005 10:20 PM
How do I change my contact information (credit card email address etc...) Jim General Questions and Comments 0 11-11-2004 08:56 PM
Changing credit cards khronos General Questions and Comments 2 03-08-2003 05:49 PM


Live Help



Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC6
vBulletin Skin developed by: vBStyles.com
Copyright © 2002 Page-Zone Web Hosting. All rights reserved.
Smilies provided by Crack's Smilies http://www.mysmilies.com