hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Ecommerce Hosting & Discussion : How do you SAFELY pass hidden variables through merchant account payment screens?
Reply

Ecommerce Hosting & Discussion Review web hosting payment processors, payment systems, merchant accounts, online banking, shopping carts and billing systems for ecommerce solutions. NOTICE: No offers or contact requests of any kind allowed.
Forum Jump

How do you SAFELY pass hidden variables through merchant account payment screens?

Reply Post New Thread In Ecommerce Hosting & Discussion Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 06-20-2006, 07:18 PM
mrsurrey mrsurrey is offline
New Member
 
Join Date: Jun 2006
Posts: 2

How do you SAFELY pass hidden variables through merchant account payment screens?


Hi everyone,

Please can you tell me how you prevent malicious manipulation of variables being passed through payment pages?

I'm setting up a jobsboard and need to send hidden variables through the payment screen (including job title, body text etc). Then if the payment is sucessful the hidden variables will be used by a script in the 'thankyou page' to insert the job advert's details into the database.

My question is how do you stop people just sending variables directly to the 'thankyou page' (without paying) to cause malicious postings (eg. spam) or alternatively getting free postings.

Thanks for any thoughts you have!

Kind Regards,


Stewart

Reply With Quote


Sponsored Links
  #2  
Old 06-20-2006, 07:40 PM
cdgcommerce cdgcommerce is offline
The E-Commerce Answer Guy
 
Join Date: Aug 2003
Location: Chesapeake, VA
Posts: 3,351
My suggestion is to have your order page submit to an internal CGI on your server... then parse out any invalid information and do your error-checking on it - and the do a "behind the scenes" POST of the information to the gateway server.

If you code in Perl, you can use LWP::UserAgent libraries and if you code in PHP, you could use CURL. (Other programming languages have their own equivalents.)

The other thing that you can do is set a referring URL check on either your script and/or on the gateway side if this is allowed. However, the cleanest and most secure option is usually to go ahead and check everything internally before submitting it behind the scenes to the gateway.

Hope that info is helpful!

__________________
CDGcommerce.com - Trusted Merchant Account Solutions since 1998
Many thousands of successful, growing businesses benefit from our expertise every day. You can, too!
We help merchants to eliminate gateway costs, reduce & mitigate fraud and achieve streamlined PCI compliance.
Learn more today at http://www.cdgcommerce.com - we look forward to helping your business grow!

Reply With Quote
  #3  
Old 06-21-2006, 11:41 AM
mrsurrey mrsurrey is offline
New Member
 
Join Date: Jun 2006
Posts: 2
Hi,

Thanks for your help, very interesting.

I'm familiar with php so i should be able to implement a referring url check. The suggestions for an internal CGI are a bit beyond my capabilities though! - if i just use a referring url checker exactly how safe is this? is it just a negligible risk?

i'm wondering whether or not to spend a couple of weeks learning how to use internal CGI and CURL or just settle for the referring url checker.

Thanks!

Stewart

Reply With Quote
Sponsored Links
Reply

Related posts from TheWhir.com
Title Type Date Posted
OpenSRS Reduces Pricing on EV SSL Certificates, Introduces UC/SAN Option Web Hosting News 2012-09-20 16:39:20
OpenSRS and Host Merchant Services Offer Resellers Payment Processing Discounts Web Hosting News 2012-04-02 12:08:26
Are you ready for the Durbin Amendment? Blog 2011-09-21 15:41:14
Saving Money while Collecting Money with Bill Ranta and Sayid Shabeer of Litle & Co Web Hosting News 2011-08-10 22:36:08
Edge Web Hosting Partners with Host Merchant Services for Payment Processing Web Hosting News 2011-07-20 18:43:55


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?