Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
SlickEdit: Code in over 40 languages across 7 platforms. SlickEdit’s unmatched power, speed, and flexibility allows even the most accomplished developers to write better code faster. Download a free trial today!
  #1  
Old March 19th, 2008, 02:53 PM
fangore fangore is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2007
Posts: 89 fangore User rank is Private First Class (20 - 50 Reputation Level)fangore User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 22 h 33 m 57 sec
Reputation Power: 1
Order security

Is there any way that i can secure my order page? Like
https://www.mypage.com/cart/
thanks,
fangore

Reply With Quote
  #2  
Old March 20th, 2008, 12:13 PM
B-Con's Avatar
B-Con B-Con is offline
Crypto-Con
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Apr 2004
Location: UC Davis
Posts: 6,633 B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level)B-Con User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 5 Days 16 h 3 m 52 sec
Reputation Power: 762
I assume you already have https enabled? Beyond that, there are a couple of things:

You need to ensure the webpage was designed securely, ie, the code of the backend language that manages your database etc isn't vulnerable to injections, etc. The guy who wrote your webpage to begin with might be a good person to start with.

You need to ensure your web server software is configured correctly. If you use Apache, you need to ensure that you have the latest security patches, that you do not have bad configurations, etc. For this you need someone with expertise with your specific server software.

You need to ensure that your web server, the machine itself, is secure. Ensure it has the latest security patches, there are no extra services running that a hacker could exploit, you have permissions and configurations set up properly, etc. For this you need someone with expertise with your OS (Linux, Windows, OpenBSD etc).

Sorry, there are no "do X and Y" steps to give, you just need a trained eye to evaluate those three aspects of your web service and comb them over.
__________________
- "Cryptographically secure linear feedback shift register based stream ciphers" -- a phrase that'll get any party started.
- Why know the ordinary when you can understand the extraordinary?


- Sponsor my caffeine addiction! (36.70 USD recieved so far -- Latest donor: Mark Foxvog
)

Reply With Quote
  #3  
Old March 20th, 2008, 02:11 PM
fangore fangore is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2007
Posts: 89 fangore User rank is Private First Class (20 - 50 Reputation Level)fangore User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 22 h 33 m 57 sec
Reputation Power: 1
I am the guy who writes the page, just new in keys / ssh

Reply With Quote
  #4  
Old March 20th, 2008, 03:33 PM
fishtoprecords's Avatar
fishtoprecords fishtoprecords is offline
Contributing User
Click here for more information.
 
Join Date: Sep 2007
Location: outside Washington DC
Posts: 897 fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level)fishtoprecords User rank is Lieutenant Colonel (40000 - 50000 Reputation Level) 
Time spent in forums: 1 Week 2 Days 22 h 38 m 54 sec
Reputation Power: 416
Quote:
Originally Posted by fangore
Is there any way that i can secure my order page? Like
https://www.mypage.com/cart/


Not sure what you are asking that B-con didn't address.
If your host has SSL setup, just change the URL to your order page to HTTPS and you are started.

Is that what you are asking?

Or are you asking about how secure is it after you use SSL?
Again, B-con has covered the high level information.

How secure is secure? Pretty much there is no such thing as absolute security. But there are things you can do to make a system more secure.

SQL injection, cross site scripting are among the many bad things that can happen.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Order security


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway