Home TheRandomizer Forum Index Log in Register FAQ Search
TheRandomizer Forum Index » General Support » BIG NEWS!!! Stormpay has FIX their Security Problem!!!!!
Post new topic  Reply to topic View previous topic :: View next topic 
BIG NEWS!!! Stormpay has FIX their Security Problem!!!!!
PostPosted: Fri Dec 12, 2003 7:18 pm Reply with quote
aboutweb
Visitor
Joined: 21 Oct 2003
Posts: 27
Location: Seattle Wa




BIG NEWS!!!!

I have been working with StormPay to get their security fixed!!
GUESS WHAT they actually replied and have FIX IT!!!

Here is a copy of their reply

I have also gone and did a hack in to see if return URL could be veiwed
IT IS FIXED!

Jim

Message
Hello Jim, My Name is Jim Grago and I am in charge of Programming and Technology here at Stormpay. Recently I was made aware of a problem that you introduced that people are able to view your source code at our payment page. I am please to let you know that my programmers have made an update that eliminates this problem.

My programmers have changed to a new technology that passes your form variables "behind the scenes" and when you goto view source on the payment page, you will see a blank "" value.

This is what my programmer wrote to me:

The data that StormPay considers sensitive (return_URL, cancel_URL, notify_URL, transaction_ref, user_id, user1 to user5 fields) are NO where insight (hidden), and that we DELIBERATELY pass those variables as BLANK in our Pay forms.

Please have a look at the checkout form now and you will see what I mean. Thank you for your input in this matter. We are striving to make Stormpay #1 in the payment processing world and its input from our members (Like you) that help us improve.

Thank you,
Jim
StormPay.com
PostPosted: Sun Jan 18, 2004 2:06 pm Reply with quote
tombrett
Visitor
Joined: 27 Oct 2003
Posts: 13




cool, at long last ...
 BIG NEWS!!! Stormpay has FIX their Security Problem!!!!! 
 TheRandomizer Forum Index » General Support
All times are GMT  
Page 1 of 1  

  
  
 Post new topic  Reply to topic  


Powered by phpBB© 2001-2006 phpBB Group |Randomizer Script | Web Hosting | phpBB Skin by Vjacheslav Trushkin