?
Solved

encrypt Decrypt problem

Posted on 2005-04-27
3
Medium Priority
?
395 Views
Last Modified: 2013-12-20
We are using the encrypt and decrypt function with Coldfusion MX 6.1. We are using it to provide a basic level of security for customers using credit cards. When the customer passes the credit through a form, it gets checked for validity and then excrypted with the use of a key produced by us and written to a SQL database. During the decryption we get odd results, it seems that the AMerican Express cards are failing and we are receiving junk, instead of the decrypted version of the card number. We are also using the function preservesinglequotes to possible avoid problems with the entry into sql.

If anyone has any ideas on this issue. i would appreciate the input.

CJSantora
0
Comment
Question by:CJSantora
1 Comment
 
LVL 35

Accepted Solution

by:
mrichmon earned 2000 total points
ID: 13877112
Well even with the preserve single quotes you could have problems with entry into SQL.

Additionally there have been articles that state things like these quotes:

"using ColdFusion's built-in functions is a good practice, but these methodologies fall a bit short when security is a real issue"

"in the case of Cold Fusion encrypt(),the key is actually passed in both the encrypt() and decrypt() functions as plain text"

"ColdFusion's encrypt() function can be decrypted, but the key must be passed in the code on the server, causing a security issue (plus encrypted data placed on the Web can be fairly easily cracked using any number of free tools available on the Internet."

Here is a link:http://coldfusion.sys-con.com/read/46359.htm

I recommend using a much more secure encryption if you are dealing with credit cards.

I have used: CFX_ENCRYPT_AES
http://www.cfxworks.com/index.cfm?fuseaction=Qnumber&Question=3-1

0

Featured Post

[Webinar] Cloud and Mobile-First Strategy

Maybe you’ve fully adopted the cloud since the beginning. Or maybe you started with on-prem resources but are pursuing a “cloud and mobile first” strategy. Getting to that end state has its challenges. Discover how to build out a 100% cloud and mobile IT strategy in this webinar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction In this tutorial, I'll explain how to create an animated progress meter in a wireframe prototype developed using Axure RP 7.0 - a leading prototyping tool for designing web sites and software. (For more information about Axure and gett…
Originally, this post was published on Monitis Blog, you can check it here . It goes without saying that technology has transformed society and the very nature of how we live, work, and communicate in ways that would’ve been incomprehensible 5 ye…
The purpose of this video is to demonstrate how to automatically show related posts at the bottom of a blog post in WordPress. This will be demonstrated using a Windows 8 PC. Plugin “Yet Another Related Posts Plugin” will be used. Go to your…
The purpose of this video is to demonstrate how to integrate Mailchimp with WordPress, by placing a Mailchimp signup form on a WordPress Page or Post. This will be demonstrated using a Windows 8 PC. Mailchimp will be used. Log into your Mailchi…
Suggested Courses
Course of the Month13 days, 16 hours left to enroll

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question