Page 1 of 2 12 LastLast
Results 1 to 10 of 20
  1. #1
    Join Date
    Dec 2008
    Posts
    12
    Plugin Contributions
    0

    Default View Full Credit Card Number

    Im using paypal direct payment pro with api.

    In my admin in only shows part of the credit card number. i would like to see the full card number. often a customer emails us to add something to an order or sometimes there was a price error and after talking to the customer they tell us to just charge the difference . however, its unprofessional to have to ask them each time for their credit card number.

    paypal does not display the number. in my paypal api logs stored on the server part of the number is xxxxx . how can i find the full number or better have the full number displayed in the admin. this is very important for us.

    can the dr. help

  2. #2
    Join Date
    Jul 2005
    Location
    Upstate NY
    Posts
    22,010
    Plugin Contributions
    25

    Default Re: View Full Credit Card Number

    You are not allowed to store the full card number on your computer, so you will never be able to display it the way you want.
    I don't know how Paypal Pro handles the numbers, so someone else will have to advise on a way to find the rest of the number.

  3. #3
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: View Full Credit Card Number

    Quote Originally Posted by abcgiftcards View Post
    i would like to see the full card number.
    Sorry, PayPal NEVER shares the customer's actual payment details with the merchant.
    Quote Originally Posted by abcgiftcards View Post
    however, its unprofessional to have to ask them each time for their credit card number.
    Actually, the opposite is true. If you tell them that your system never stores their actual credit card number once payment is collected, and that's so their financial information is kept private in the name of security, then it's quite likely they'll be very understanding and give you the number to process an additional charge.
    You can talk to PayPal support about the matter if you like ... they're going to tell you the same thing: "sorry, the CC info is private".

    Quote Originally Posted by abcgiftcards View Post
    often a customer emails us to add something to an order or sometimes there was a price error and after talking to the customer they tell us to just charge the difference .
    If this is a *common* occurrence on your site, then I suggest two things:
    a) work on helping your customers not make mistakes when placing orders. Having to make price adjustments because of customer confusion is IMO the part that's unprofessional. Perhaps you have things on your site that are unclear to the customer. Fixing that would save you a lot of administrative trouble.

    b) You could set up your PayPal module to operate in "authorize only" mode instead of "authorize and capture" mode. That way before you actually settle EACH AND EVERY transaction you can verify the price and then capture the correct amount, at which point the card is actually charged. However, PayPal has some limits on whether they'll allow you to capture more than the original authorization amount. But doing it this way means you'll be manually completing EVERY order's payment details.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Dec 2008
    Posts
    12
    Plugin Contributions
    0

    Default Re: View Full Credit Card Number

    the order issue with mistakes is not that common. what is more common is customers call us up to add things to there order. instead of asking them for their number we would rather have it.

    if zencart cannot store numbers how do you do it when you install the module for offline cc transactions?

    is there a way to at least have part of the numbers emailed to me with api processing just like it can be done with the basic credit card processing?

  5. #5
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: View Full Credit Card Number

    You can do anything you like with custom coding. However, ANY discussion of storing credit card numbers in the database is not to be posted on the forum, as it is not only dangerous but is contrary to your merchant account TOS and not compliant with PCI security standards. If you want to alter the code, feel free. If you want to hire someone to do it, make sure they are fully aware that what you're asking to do is dangerous and has security implications and under what terms you are engaging them in terms of liability. And if you post the code or share it with others, you may or may not be held responsible for its misuse.

    As for the "offline" module ... it's being removed from Zen Cart in v1.3.9 for this and other reasons.

    But, you can certainly change the code if you desire to do so ... at your own risk.

    (Sorry for the heavy reply ... but it's crucial that you understand the security aspect.)
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Oct 2006
    Posts
    5,477
    Plugin Contributions
    11

    Default Re: View Full Credit Card Number

    Just for your information, one of my customers almost got terminated from EVERY merchant provider for violating this term. It's lucky that we found this out before any incident took place.
    I no longer provide installation support on forum for all my modules. However, if there are real bugs with the modules please feel free to contact me

  7. #7
    Join Date
    Jan 2009
    Posts
    25
    Plugin Contributions
    0

    Default Re: View Full Credit Card Number

    interesting topic. i was just pondering about the security implications for customers and vendors.

    basically... "omg! if one thousand credit card details were stored, and each card has a limit of say twenty grand, then ... that is twenty million dollars worth of credit that the vendor is being entrusted with!"

    i think it is great that the offline module is being removed in version 2.0

  8. #8
    Join Date
    Jan 2009
    Posts
    54
    Plugin Contributions
    0

    Default Re: View Full Credit Card Number

    Quote Originally Posted by DrByte View Post
    You can do anything you like with custom coding. However, ANY discussion of storing credit card numbers in the database is not to be posted on the forum, as it is not only dangerous but is contrary to your merchant account TOS and not compliant with PCI security standards. If you want to alter the code, feel free. If you want to hire someone to do it, make sure they are fully aware that what you're asking to do is dangerous and has security implications and under what terms you are engaging them in terms of liability. And if you post the code or share it with others, you may or may not be held responsible for its misuse.

    As for the "offline" module ... it's being removed from Zen Cart in v1.3.9 for this and other reasons.

    But, you can certainly change the code if you desire to do so ... at your own risk.

    (Sorry for the heavy reply ... but it's crucial that you understand the security aspect.)
    You can store and display credit card information on your website from your shopping cart database if your website AND your company are PCI DSS Compliant. This means that in addition to your website being security scanned (quarterly) by an ASV (Approved Scanning Vendor) service, you have also filled out the Self Asscessment Questionaire and mailed it to your merchant processor for their records.

    There are a minimum of 12 Self Asscessment Questions you must answer (more depending on your selling volume) - one pertains to your SSL Certificate, one pertains to your having an ASV scan your website server quarterly (or annually depending upon what Level you fall under) and rest are administrative security questions.

    Unless I am mis-understanding this thread and your post specifically, you make it sound like you cannot or should not, be displaying credit card numbers in Zen Cart (or any other shopping cart).

    How do you run a business if, after the customer enters an order, you cannot ever see their CC information? PCI DSS certification was designed so that you could do this and be as secure about it as possible. Remember, the PCI DSS security standards were created by the big four credit card companies.

  9. #9
    Join Date
    Oct 2006
    Posts
    5,477
    Plugin Contributions
    11

    Default Re: View Full Credit Card Number

    @rfresh: you missed the main point.
    For most small business, you dont have to and shouldnt store the CC numbers. There are merchant service providers such as Linkpoint, Paypal, Authorize,.... that store these numbers for you.

    In most cases, it is a safer choice to leave those numbers in their hands and have them take full responsibilities of safe guarding those.

    Most users here run their cart on a shared hosting, and most of them have no clue about securing their sites.
    I no longer provide installation support on forum for all my modules. However, if there are real bugs with the modules please feel free to contact me

  10. #10
    Join Date
    Feb 2004
    Location
    Simcoe, Ontario, Canada
    Posts
    2,479
    Plugin Contributions
    1

    Default Re: View Full Credit Card Number

    All of you have *some* valid points in your posts.

    In reading emerging industry standards for security, The credit card vendors have upped their standards recently. I really cannot remember the exact proposed date but they are requesting that all OCC's are to be encrypted now.

    I am trying to find in my browser history which site I read that on...

    If someone recently read it, could you please post that article url.
    Windows, BSD, Linux, Cisco, Hardware & IT Security Tech
    AEIIA - Zen Cart Certified & PCI Compliant Hosting

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 5
    Last Post: 29 Nov 2010, 06:28 AM
  2. Full Credit Card Info for Recurring Charges
    By softwebsolutions in forum Built-in Shipping and Payment Modules
    Replies: 1
    Last Post: 20 May 2009, 03:11 AM
  3. Is it possible to have the full credit card displayed in admin??
    By tlyczko in forum Built-in Shipping and Payment Modules
    Replies: 1
    Last Post: 21 Oct 2008, 02:01 PM
  4. Full Credit Card Number in e-mail
    By quantum in forum Built-in Shipping and Payment Modules
    Replies: 21
    Last Post: 10 May 2007, 04:23 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg