Solved

Credit card security

Posted on 2001-06-15
12
238 Views
Last Modified: 2013-12-24
How can i send securely Credit card information to the server after form submisson using ColdFusion?
Is it necessary to have SSL installed on the server?
Where can i get information regarding?
Is there any custom tag that securely sends Credit card information to the server? Pl. help...
0
Comment
Question by:manoher
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
  • 2
  • +3
12 Comments
 
LVL 3

Expert Comment

by:TEFKASG
ID: 6196772
>>Is it necessary to have SSL installed on the server?

  Actally that's all you need as far as I know.  I don't know if Cold Fusion has any special tags for it, as I haven't had to use any.  :>)
0
 
LVL 3

Expert Comment

by:TEFKASG
ID: 6196790
0
 
LVL 3

Expert Comment

by:TEFKASG
ID: 6196802
Also they can send you load of info on web business security.  :>)
0
How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

 
LVL 3

Expert Comment

by:TEFKASG
ID: 6196814
Here for the gerneral site overview:

https://www.verisign.com/
0
 
LVL 3

Expert Comment

by:TEFKASG
ID: 6196817
0
 
LVL 37

Expert Comment

by:meverest
ID: 6197078
for ssl, don't overlook www.thawte.com - in many cases cheaper, in some cases easier, and just the same result.

for credit card processing, you could also look at a solution like this: www.xilo.com/veripay - that is one for australian $$ - not sure of any in other currencies.

cheers.

0
 
LVL 37

Expert Comment

by:meverest
ID: 6197082
oh - what i meant to say about that veripay service is that if you use something like that, you don;t even need SSL coz the system provides SSL already.

cheers.
0
 
LVL 11

Expert Comment

by:jimmy282
ID: 6197675
what about autorize.net

their website is http://authorizenet.com

Jimmy
0
 
LVL 19

Expert Comment

by:cheekycj
ID: 6198492
SSL is not something you should purchase from a third part.. your web service provider should already have it.

The setup process should be...
your billing form doesn't need to be but for user's piece of mind should be on SSL port.

The page that is submits to MUST be on SSL no matter what.

I also recommend authorize.net, mentioned by Jimmy.  I use them and they are very good.

CJ
0
 
LVL 19

Accepted Solution

by:
cheekycj earned 100 total points
ID: 6198495
FYI: SSL is encryption at the network layer.. so no sw or custom tags are needed... any and all information that is communicated over an SSL port is encrypted by the server and sent over.. so you don't have to worry about implementing an encryption scheme or using some encryption algorithm.

CJ
0
 

Expert Comment

by:tionghoe
ID: 6198706
There are 2 parts to the issue. SSL encryption must be configured on the web server. Configurations include the encryption levels (128,56 or 40-bits encryption), the SSL port (normally is 443) to be used and which of the web directories is to use the SSL. You may need to have a SSL certificate installed on the web server. The SSL certificate may be purchased from a CA.
0
 

Expert Comment

by:hansamryan
ID: 6229097
You might want to use an encryption method once it card is put into the DB, because sure the SSL encrypts it from the pc-->Server but from there its up for grabs.
0

Featured Post

Secure Your WordPress Site: 5 Essential Approaches

WordPress is the web's most popular CMS, but its dominance also makes it a target for attackers. Our eBook will show you how to:

Prevent costly exploits of core and plugin vulnerabilities
Repel automated attacks
Lock down your dashboard, secure your code, and protect your users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Periodically we have to update or add SSL certificates for customers. Depending upon your hosting plan you may be responsible for the installation and/or key generation. In the wake of Heartbleed many sites were forced to re-key. We will concen…
This guide will walk you through the essential considerations and tech stack for building scalable websites. Know how to grow your business the smart way!
The purpose of this video is to demonstrate how to exclude a particular blog category from the main blog page. This is can be used when a category already has its own tab, or you simply want certain types of posts not to show up on the main blog. …
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question