Dastar...
Your Source For Information
46443 Articles Listed





Search:



How to Stop Digital Thieves with CGI

I'm going to assume you're serious about your business. If
you're not, I can't help you anyway. You've gone as far as
getting a real merchant account to accept credit card payments
online.

You know that this was neither easy or cheap. So does everyone
else! So, a merchant account shows that you've made a serious
commitment to your business. That's good for customer
confidence, which is good for business. So far so good...

Now there's the issue of selling stuff to people online. Your
order form leads them to feed their credit card info to a secure
gateway, using software you bought or leased from (or through)
your merchant account provider. Finally, the transaction is
approved or denied.

If approved, the software generates a receipt and emails you
and the customer each a copy. At this point, the customer is
returned to a page you specified. In the case of downloadable
products, this is often the page where they download your
product. So, you've got the entire process fully automated.

For a product or service with a fairly low price point and a
potential for many thousands of sales, this seems ideal. You can
quite literally make sales and earn income 24 hours a day. So,
what's the problem?

The form code on your order page is the problem. If someone
uses the ViewSource function of their browser, they can see all
your code. If they have even a tiny bit of initiative and skill,
they can locate the URL of your download page. After all, it's
right there in your form code!

CGI provides two ways of fixing this problem. One involves
using a script that makes it impossible to view the source code.
You can find a source for such a script by searching the web.
Expect to pay a lot for this technology.

Another way is to make the return path a script instead of the
actual download location. The script would be used to create and
display the download page. It would not be visible to the
surfer, since it's not an HTML document. The script can also
record details of the transaction for book-keeping purposes.

I admit that I discovered this by trial and error - and a lucky
guess or two. Your merchant account gateway software may have
radically different behavior than mine, but here's what I've
learned:

The gateway uses the POST method to send the customer to your
specified return URL (which can be a script as well as a web
page). It also POSTs most of its input data items at the same
time. They are usually ignored, but your script can read them if
you want to!

Use the names given to the form inputs. Have your script
extract the values of these "named parameters" at the time it
creates the download page. Record what you want to save about
the transaction in your orders file or database.

Now here's the real secret to foiling the thieves. Inside the
script, check to see that the variables you extract contain
non-empty values. Did you get that? Here's an example:

if ($email eq "") {exit;}

In this example, the script expects to get an email address. If
it contains no characters, the script quits instantly. By
testing for the presence of some data in such fields as customer
name, email address, item #, price, etc., you can tell whether
the script was called after a successful transaction - or by a
thief...

Put all your security checks prior to the code that creates the
download page. If any test fails, the script exits and the thief
is left empty- handed. If your form-handling script can convert
a product name to a product ID that's never visible to a
browser, this provides even more security. This will be POSTed
back to the script and you can check for it before allowing the
download.

Close these security holes and you'll make more money. You may
even sleep a little better knowing that people can't steal that
product you worked so hard to create. I know I do!


About the Author

Steve Humphrey promises that you can learn to use CGI to turn
your own website into a marketing machine in two hours or less
with his excellent CGI learning system: "Learn to Use CGI in 2
Hours." We highly recommend this book as required reading for
anyone who wants to automate their website or their marketing
efforts. Click here for immediate access:
http://www.roibot.com/tk_cgi2h.cgi?cgiAV2b
Item Bids Price Ends
How to Draw Wings and Wheels (1999)
How to Draw Wings and Wheels (1999)
0
$0.99
5d 6h
Outdoor Wood Burner Boiler Furnace #1 plan How To Build
Outdoor Wood Burner Boiler Furnace #1 plan How To Build
$38.95
5d 6h
ELECTRONICS ELECTRIC TRAINING COURSE MANUAL HOW TO CD
ELECTRONICS ELECTRIC TRAINING COURSE MANUAL HOW TO CD
ELECTRONICS ELECTRIC TRAINING COURSE MANUAL HOW TO CD
$8.97
5d 6h
Pokemon: How to Draw by Tracey West (2003)
Pokemon: How to Draw by Tracey West (2003)
0
$0.99
5d 6h
How to Overcome Fear by Marcos Witt (2007)
How to Overcome Fear by Marcos Witt (2007)
0
$1.00
5d 6h
Remembering How to Drum Djembe DVD Video Lesson
Remembering How to Drum Djembe DVD Video Lesson
Remembering How to Drum Djembe DVD Video Lesson
$27.95
5d 6h
Rod handbook no 2  how to soup up 1961
Rod handbook no 2 how to soup up 1961
0
$5.95
5d 6h
Selling Dreams: How to Make Any Product Irresistible, G
Selling Dreams: How to Make Any Product Irresistible, G
0
$3.29
5d 6h
How to Become an Employer of Choice by Joyce L. Gioi...
How to Become an Employer of Choice by Joyce L. Gioi...
How to Become an Employer of Choice by Joyce L. Gioi...
$4.00
5d 6h
NEW How to Mow Lawn Book - Lost Art of Man Sam Martin
NEW How to Mow Lawn Book - Lost Art of Man Sam Martin
0
$0.99
5d 6h
TANDY LEATHER HOW TO LACE BOOK NEW!!!!
TANDY LEATHER HOW TO LACE BOOK NEW!!!!
$2.95
5d 7h
Outdoor Wood Burner Boiler Furnace plan #3 How To Build
Outdoor Wood Burner Boiler Furnace plan #3 How To Build
$38.95
5d 7h
NEW How to Heal a Broken Heart in 30 Days: A Day-By-...
NEW How to Heal a Broken Heart in 30 Days: A Day-By-...
1
$8.63
5d 7h
How to Make Soap in a day Step X Step DVD
How to Make Soap in a day Step X Step DVD
0
$9.99
5d 7h
How to Succeed in Business Without Really Trying (WS)
How to Succeed in Business Without Really Trying (WS)
0
$14.95
5d 7h
How to Play Rhythm Guitar Lessons Tips from Masters
How to Play Rhythm Guitar Lessons Tips from Masters
How to Play Rhythm Guitar Lessons Tips from Masters
$11.70
5d 7h
HOW TO LIVE - HYGENE, DIET, HEALTHFUL LIFESTYLE, 1932.
HOW TO LIVE - HYGENE, DIET, HEALTHFUL LIFESTYLE, 1932.
0
$5.95
5d 7h
~EV~ ELECTRIC VEHICLE  HOW TO CONVERT YOUR CAR GUIDES~~
~EV~ ELECTRIC VEHICLE HOW TO CONVERT YOUR CAR GUIDES~~
~EV~ ELECTRIC VEHICLE  HOW TO CONVERT YOUR CAR GUIDES~~
$7.95
5d 7h
SINGER HOW TO SEW BOOKS TAILORING ACTIVEWEAR FIT.
SINGER HOW TO SEW BOOKS TAILORING ACTIVEWEAR FIT.
0
$7.99
5d 7h
How to Clean Practically Anything by Consumer Report...
How to Clean Practically Anything by Consumer Report...
0
$0.99
5d 7h
Consumer Reports Books How To Clean Practically Anythin
Consumer Reports Books How To Clean Practically Anythin
0
$0.99
5d 7h
How to Find a Teaching Job: A Guide for Success (Prenti
How to Find a Teaching Job: A Guide for Success (Prenti
0
$1.00
5d 7h
How To Host A Murder ARCHAEOLOGICALLY SPEAKING Game NIB
How To Host A Murder ARCHAEOLOGICALLY SPEAKING Game NIB
How To Host A Murder ARCHAEOLOGICALLY SPEAKING Game NIB
$14.99
5d 7h
How to Eat Fried Worms (2006, DVD) Used
How to Eat Fried Worms (2006, DVD) Used
0
$4.99
5d 7h
How to instructional DVD videos Routing Wood Signs 1211
How to instructional DVD videos Routing Wood Signs 1211
0
$70.00
5d 7h
  View all items on eBayDisclaimer  
These results were generated from eBay on 01-6-2009 7:35 am.
eBay Marketplace
How to Stop Digital Thieves with CGI