osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

Credit Card info not emailed!

This is a discussion on Credit Card info not emailed! within the osCommerce 2.2 Modification Help forums, part of the osCommerce 2.2 Forums category; Hello, An email to buyer and shop owner is sent on purchase but there is no credit card info if ...


Go Back   osCommerce and osCMax shopping cart software forums > osCommerce 2.2 Forums > osCommerce 2.2 Modification Help

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 11-24-2002, 02:34 PM
Anonymous
Guest
 
Posts: n/a
Default Credit Card info not emailed!

Hello,

An email to buyer and shop owner is sent on purchase but there is no credit card info if being used manually. How does one include this in the email?

Also, is there extra code somewhere that will send half of the card # to shopowner with the name and on clicking a link go back to a page to see the complete number. This way the complete number does not exist anywhere.

We had this written for another membership site we have. It works great!

But first, why don't I get the credit card info ?

Bill
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 11-24-2002, 07:45 PM
Anonymous
Guest
 
Posts: n/a
Default

As long as you having that problem that would mean that you are one step(may be more ) ahead of me.I'm still having a problem on getting my shop accept credit cards.I want to do offline CC processing the only problem is that I can't get it to accept CC numbers.In the checkout page, the payement method is empty and it allows you to finish up the order without taking the proper informations.Am I missing something??
Any help would be reeeally appreciated.
Cheers.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 11-24-2002, 09:28 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,078
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Oh NO!

First, CC info should NEVER be sent through email. EEK! That is really asking for trouble. I have never used this option before, but I think the CC's are put in the database. You may have to check there.

As a responsible e-commerce shop owner, I suggest you avoid emailing credit card numbers, unless you encrypt the email (128 bit minimum). If anyone got news that you were emailing clear cc#'s, there would be a free for all as cc#'s = FREE MONEY to criminals. I don't think your customers would be too happy if they found out your were so lax in your security measures.
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 11-24-2002, 11:38 PM
Anonymous
Guest
 
Posts: n/a
Default

Thank you for the reply. and yes I do understand the potential hazzards with CC's via email however with the 128 encrypt it is pretty safe.

Most of the sites we deal with are all low profile sites and do not have the resources to use the bank gateway systems as some of our larger clients do.

That's why we still need somehow to allow them to be able to do it the manual way. We have a couple of other shops where it is used and hoped that we could use it at 'our peril' with this shop.

We basically needed to know what code we would have to change to actually get the cc numbers sent. We will try and get our php programmer to get half by the initail order email and use a link to get back to a page where the other half will be exposed only while the page is shown.

It then would have to be manually written down as one would do if it was a telephone order.

Thanks again
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5  
Old 11-25-2002, 06:21 AM
Active Member
 
Join Date: Oct 2002
Location: Arkansas
Posts: 149
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
modom
Default

The credit card numbers are in the database.

Why can't the store owner log into their admin area and retrieve the cc number? All of the info is in there and they can even print out an invoice.

Then, after the product has been sent to the customer they need to delete the order from the admin.

It's always good to be extra safe.
__________________
Sincerely,
Melinda

www.designhosting.biz
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6  
Old 11-25-2002, 07:50 AM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,078
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default There is a contribution for this...

I looked a little deeper into this issue, and found a contrubution at http://forums.oscommerce.com that encrypts the email before it is sent.

Here is the link:

http://www.oscommerce.com/downloads....ntributions,66

I think I saw a few threads that discussed encrypting the cc# in the database as well. Do a search on "encrypt" over at http://forums.oscommerce.com and you will get lots of good reading material.
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #7  
Old 11-25-2002, 07:27 PM
Anonymous
Guest
 
Posts: n/a
Default Re: Oh NO!

Not sure I agree. When I got my merchant acct I called the company's security dept and asked if they had any problem with sending CC#s by email and they said no, that statistically they were far more likely to be stolen by someone at my end, and that the chances of that were miniscule compared to them being stolen in a restaurant. Since then it seems to me everytime I hear of CC3s being stolen on the net it is from the database on a SECURE SERVER.

Can't remember who said the reason he robbed banks was because that was where the money is, but CC#s are the same - you want them you look on an Ecommerce site, not in email becaue there is just too much of it, perfect camoflauge.

BTW there was a now defunct shopping cart that had a very simple method of semi incryption, it would add extra digits to the CC number which you would then remove at your end - would also confuse sniffers looking for 16 digit strings.






Quote:
Originally Posted by msasek
First, CC info should NEVER be sent through email. EEK! That is really asking for trouble.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Credit card module clauska osCMax v2 Customization/Mods 0 06-15-2006 07:42 AM
Help with EPN credit card processing joanstead osCommerce 2.2 Modification Help 1 03-08-2005 05:55 PM
credit card info doesn't show in authorize.net module gmartini42 osCMax v1.7 Discussion 1 02-15-2005 09:55 PM
Credit card month... damos osCommerce 2.2 Modification Help 1 04-10-2003 01:21 PM
credit card transactions alisonpurcell osCommerce 2.2 Installation Help 1 04-07-2003 10:43 AM


All times are GMT -8. The time now is 04:10 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax