Click here to register.
      
PBWG Banner


     eCommerce solutions and SSL security. > SSL security.

eCommerce solutions and SSL security.

User aewhale
Date 8/6/2008 3:01 pm
Views 332
Rating 0    Rate [
|
]
Previous · Next
User Message
aewhale

<Begin SoapBox>

As a Security Consultant, the Point to point encryption of eCommerce solutions is essential to maintaining the security and integrity of a web based eCommerce solution.

Case in point are the 40+ Million Credit Cards that the FBI (Justice Department) now has charged 11 people with Identity Fraud, and hacking of Computer Systems.

As a Security professional, I am telling you that WarDriving (the remote exploiting of Wireless communications), key stroke loggers, and network sniffing are just some of the techniques employed in gaining access to the personal information.  Some, if not all, of this could have been avoided with the use of better security (wireless security certainly), and encryption technologies (like SSL).

Employing security from the design up, is significantly easier to implement than after a breach has been encountered.

</End SoapBox>


That being said, I am anxiously awaiting the release of the 7.5 WebGui code, with Shopping Carts.  Having spoken with Sr. developer - Doug Black, I agree that the intent of the WebGui design is to not store the Credit Card information in the system, and permit the processing to occur (even recurring charges) at the payment gateway.

While I also employ a Fresside Billing system (design by Ivan Kohler - developer of the CPAN Business::OnlinePayments modules), which exclusively uses SSL (https connections) for all of the connections, whether it's a remote gateway, or credit card processor.

 

My hope is that WebGui intends to use Best Practices and employ a rigid use of SSL connectivity in anything involving the Shopping Carts, or eCommerce interfaces.



Back to Top
Rate [
|
]
 
 
colink

It seems odd to me, with WebGUI being open source, and publicly available SVN repositories, that you'd soapbox before checking out the source code.



Back to Top
Rate [
|
]
 
 
pwrightson

Hey guys,

Can you test this and let me know - cause I think this could be a problem (or I just may have my SSL set up wrong!).

Standard WRE site, add SSL.

Add a page that should be visible with SSL only using 'encrypt content' (https://<MY-DOMAIN>/home/test-ssl).

Try viewing the page without SSL by removing the 's' off the end of the 'https' in the URL and you get redirected to the SSL version.

Login, turn Admin on and go to edit the page. Now, remove the 's' and make the URL non-ssl again and try it. (http://<MY-DOMAIN>/home/test-ssl?func=edit)

It looks like I can edit an SSL-only page without SSL - I think that would be a problem. This is 7.5.10.

Thoughts?

 



Back to Top
Rate [
|
]
 
 
JT

You're right that you can edit the page without SSL mode on. That's cuz the feature is there to force it for end users, and end users can't edit the page. I'm not saying that we couldn't/shouldn't also force SSL on editing, deletion, etc, just that it wasn't designed to support that. If you'd like to see that changed then by all means submit an RFE for it.



Back to Top
Rate [
|
]
 
 
pwrightson

It occurs to me that this probably occurs whenever a func=?? or op=?? is used.

I am going to investigate a little further and then write the RFE.

Thanks, Paul W



Back to Top
Rate [
|
]
 
 
JT
Yes it does

JT
On Aug 9, 2008, at 9:46 AM, <paul@pwrightson.com> wrote:

pwrightson wrote:

It occurs to me that this probably occurs whenever a func=?? or op=?? is used.

I am going to investigate a little further and then write the RFE.

Thanks, Paul W



http://www.plainblack.com/webgui/dev/discuss/ecommerce-solutions-and-ssl-security/4


--

Plain Black&#44; makers of WebGUI
http://plainblack.com


Back to Top
Rate [
|
]
 
 

Re: Pagination and Navigation Menus. by rogier - Wed @ 08:43am

Re: Pagination and Navigation Menus. by eleger81 - Wed @ 08:16am

Re: perl module installation fails by knowmad - Wed @ 07:44am

Re: perl module installation fails by jonie_e2000 - Wed @ 06:20am

Smoketest For nightly_2008-08-20 by Visitor - Wed @ 01:44am

Re: Pagination and Navigation Menus. by rogier - Tue @ 04:20pm

Re: Pagination and Navigation Menus. by eleger81 - Tue @ 03:15pm

Re: spectre.pl cannot be started by susanb - Tue @ 03:09pm

Re: Help with show hide JS by sandraqu - Tue @ 03:02pm

spectre.pl cannot be started by zefo - Tue @ 02:27pm

Re: Pagination and Navigation Menus. by rogier - Tue @ 01:33pm