osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Credit Card Email of 8 middle digits

This is a discussion on Credit Card Email of 8 middle digits within the osCMax v2 Customization/Mods forums, part of the osCMax v2.0 Forums category; Just wondering where I could edit the email that is sent to the store owner. My client would like a ...



Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > osCMax v2.0 Forums > osCMax v2 Customization/Mods

Connect with Facebook Register FAQDonate Members List Calendar Mark Forums Read


Closed Thread

 

LinkBack Thread Tools
  #1  
Old 09-28-2008, 02:19 AM
Member
 
Join Date: Jun 2008
Posts: 57
Thanks: 1
Thanked 0 Times in 0 Posts
Rep Power: 2
kerryanne is on a distinguished road
Default Credit Card Email of 8 middle digits

Just wondering where I could edit the email that is sent to the store owner.

My client would like a bit more information such as customer contact details and email address to go with it.

Currently all that is sent is

Order #

8 middle digits
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2  
Old 09-28-2008, 10:34 AM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 15,746
Thanks: 139
Thanked 609 Times in 521 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Credit Card Email of 8 middle digits

Do not use the cc.php module for production sites. It is there only for testing purposes while you get your store set up. It is NOT secure and should NEVER be used with real cc numbers. It does not meet the minimum rules for transmission of CC info set forth by any credit card company. Get a real time processor that encrypts all transactions and removes the CC# storage responsibility from you.

The hacking community is well aware of that module and can easily identify sites using it for real orders. It puts a big bullseye on sites using it.

Do you fully realize what you are asking to do? Basically provide most of the CC#, name, address, and email in a cleartext email that anybody with basic hacking skills can intercept and use to steal an identity or commit other fraud. If someone with bad intentions wanted to commit fraud with this info, it would be very easy - trust me, I have seen how easy.

Aside from the fact that it shows blatant disregard for the customer's data safety, it is very risky and may even be illegal in some locales.

I suggest you talk your client into the proper way to do business on the internet. Get a real time processor/gateway that is secure. Process the cards in real time and store no credit card data, and most of all do not transmit that data un-encrytped (like you are asking to do). If you explain the risks involved, the tiny fee increase of getting a payment gateway set up is well worth the effort.
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 09-29-2008, 12:52 AM
Member
 
Join Date: Jun 2008
Posts: 57
Thanks: 1
Thanked 0 Times in 0 Posts
Rep Power: 2
kerryanne is on a distinguished road
Default Re: Credit Card Email of 8 middle digits

Yes I agree with you completely on the email front but its what she wanted but we werent going to have the CC number get emailed, just more of the orders details.

I didnt know we shouldnt use the normal CC function.

My client has a payment gateway, the paypal payflow but I cant get it to work and shes wanting the site live tonight.

Arghhh is there someone who can help with this?

She also has regular paypal on the site at the moment. I guess thats all shes going to get at the moment.

On another note.
She does not receive an email when a customer makes an order, isnt that a default feature?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 09-29-2008, 09:04 AM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 15,746
Thanks: 139
Thanked 609 Times in 521 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Credit Card Email of 8 middle digits

That is not what your initial post says.

Quote:
Order #

8 middle digits
From what that first post says, you want to add the customer details to the above information. If that is the case, that is a completely insecure setup. You simply should never use the cc.php module for a production site. Emailing even a portion of the actual credit card number is a violation of your merchant agreement and if your processor finds out, they will terminate the agreement or worse. Hackers depend on merchants doing silly things like emailing credit card numbers or storing them in clear text. It makes stealing them so easy.

If your actual payment processor is not working, you simply should not go live until it is working. That is just common sense.

If you have paypal working, go live with it, and when you get the configuration for the other gateway completed bring it online.
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Credit Card with CVV2 michael_s New osCommerce Contributions 0 08-08-2008 04:01 PM
Never See Credit Card v1 michael_s New osCommerce Contributions 0 01-25-2008 12:10 PM
Never See Credit Card v1 michael_s New osCommerce Contributions 0 01-25-2008 11:00 AM
GPG with CVV2 and Blank GPG Email no credit Card Number? tmullins osCMax v2 Customization/Mods 1 12-26-2005 08:31 PM
8 digits credit card altenter osCMax v1.7 Discussion 9 08-20-2004 07:07 AM


All times are GMT -8. The time now is 09:48 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2009 osCMax
Inactive Reminders By Icora Web Design