Results 1 to 7 of 7
  1. #1
    Join Date
    Jun 2006
    Location
    Providence
    Posts
    137
    Plugin Contributions
    0

    Default 2 security questions

    I just designed my web site using ZenCart and am planning on putting it up on the server next week. I'm still in the process of getting e-commerce set up, so I'm just going to make it a showcase until I'm ready. My question is about credit card numbers. Are they stored on the server, in the database or via the payment gateway? If via the payment gateway, I assume that nothing about users' credit cards will be stored on the web site. I'm probably going to use Authorize.net. Pay Flo Pro isn't supported in Zen Cart. At elast not yet.

    I also have a security qwuestion about the admin folder. I thought at one point I had read that it's a good idea to change the name of the admin folder for security reasons. Did I dream this or is it true?

  2. #2
    Join Date
    Feb 2006
    Location
    Chicago
    Posts
    1,162
    Plugin Contributions
    0

    Default Re: 2 security questions

    Quote Originally Posted by kjharrison
    I just designed my web site using ZenCart and am planning on putting it up on the server next week. I'm still in the process of getting e-commerce set up, so I'm just going to make it a showcase until I'm ready. My question is about credit card numbers. Are they stored on the server, in the database or via the payment gateway? If via the payment gateway, I assume that nothing about users' credit cards will be stored on the web site. I'm probably going to use Authorize.net. Pay Flo Pro isn't supported in Zen Cart. At elast not yet.

    I also have a security qwuestion about the admin folder. I thought at one point I had read that it's a good idea to change the name of the admin folder for security reasons. Did I dream this or is it true?
    For #2, they ask to change the name of the admin folder since when you keep the default admin folder, anyone can make an attempt to enter into admin using cart/admin path
    Also, it would be more safe if you can put an IP check for admin that when your IP(s) is there then only let the admin open ( Can be done through .htaccess)

  3. #3
    Join Date
    Jun 2006
    Location
    Providence
    Posts
    137
    Plugin Contributions
    0

    Default Re: 2 security questions

    Quote Originally Posted by superprg
    For #2, they ask to change the name of the admin folder since when you keep the default admin folder, anyone can make an attempt to enter into admin using cart/admin path
    Also, it would be more safe if you can put an IP check for admin that when your IP(s) is there then only let the admin open ( Can be done through .htaccess)
    My IP changes, so I don't htink the .htaccess will work for me.

  4. #4
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: 2 security questions

    as for your first question

    this is a several part answer.
    If you use the stock credit card module.
    zen cart will store 1/2 of the number and email you the other 1/2 and the cvv

    if you are using authorize.net then no the numbers do not get stored in the database.

    and as far as I know payplow pro works with zen cart.
    Zen cart PCI compliant Hosting

  5. #5
    Join Date
    Feb 2006
    Location
    Chicago
    Posts
    1,162
    Plugin Contributions
    0

    Default Re: 2 security questions

    Quote Originally Posted by kjharrison
    My IP changes, so I don't htink the .htaccess will work for me.
    No problems, you can atleast change the admin folder name

  6. #6
    Join Date
    Jun 2006
    Location
    Providence
    Posts
    137
    Plugin Contributions
    0

    Default Re: 2 security questions

    Quote Originally Posted by superprg
    No problems, you can atleast change the admin folder name
    I plan opn doing that. Thank you. Will I have to change any other files?

  7. #7
    Join Date
    Feb 2006
    Location
    Chicago
    Posts
    1,162
    Plugin Contributions
    0

    Default Re: 2 security questions

    Quote Originally Posted by kjharrison
    I plan opn doing that. Thank you. Will I have to change any other files?
    Yes, you would have to make changes in the admin/configure.php
    Simply renaming the folder name might land you in trouble!
    SAn

 

 

Similar Threads

  1. Upgrade Questions re: Security & Templates
    By janissaire in forum All Other Contributions/Addons
    Replies: 3
    Last Post: 17 Aug 2010, 04:20 PM
  2. Security Patch Questions
    By steveb8385 in forum General Questions
    Replies: 7
    Last Post: 21 Sep 2009, 02:47 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg