E-commerce site and security

I am likely to begin working on a large e-commerce site soon and would like to get everything straight before I begin.
I have a reseller account on a virtual dedicated server at the hosting provider everyone loves to hate. Generally my modus operandi is to create a folder and point a subdomain to that folder so the client can see the site. Unless there are serious security issues or the need for a huge amount of server space, I leave the site in that folder and point to domain name to it when it is completed.
Does an e-commerce site need to be on a dedicated server as a matter of prinicple? If I use Cartweaver or VirtueMart and a payment gateway such as Paypal or Authorize.net, does it matter if the site is on a dedicated server behind SSL? Or can I simply leave it on my hosting account and put the Paypal Verified graphic on the site?
Or could I create a new virtual dedicated reseller account just for e-commerce sites? Or would an economy account suffice?
The issue of testing in one account  and then moving to another is one I don't like. Do you have a way of testing and cloning the site?

Hello Peavo,
A shared host is fine for e-commerce... But let me qualify this by adding - a shared host that KNOWS e-commerce and how to help you attain PCI certification, and  - this is really an important one - offers very good, quick, support! If your revenue generating site is down you want help NOW, not a "call back" or an email a day or two from now.  I echo the statement that you should avoid GoDaddy, more like run screaming in the other direction.  They, and many cheap, super high volume hosts, are fine for run of the mill HTML sites or even the occasional WordPress blog, but for the complexities of and security required by an e-commerce site they are woefully inadequate.
All that being said, there are literally thousands of Cartweaver , and other e-commerce sites happily motoring along on quality shared hosts. So with some caution and having your homework done, there's no worries there.  I can recommend GoWestHosing.com - very good smaller host that specializes in dynamic and e-commerce sites and knows all the ins and outs of PCI compliance.
If you expect to have an extremely high volume site, then looking into a VPS is not a bad idea, but truthfully, for most average shopping cart sites a quality shared hosting account will do, and cost significantly less.  You could start out with a hosted account, then always migrate to a VPS if need be.
Here's a blog post about PCI that you may find helpful.
http://blog.cartweaver.com/?s=PCI
Hope this helps!
Lawrence Cramer - *Adobe Community Professional*
http://www.Cartweaver.com
PHP & ColdFusion Shopping Cart for Adobe Dreamweaver
Stay updated:
http://www.facebook.com/cartweaver
http://www.twitter.com/cartweaver
http://blog.cartweaver.com

Similar Messages

  • What a shambolic web site and security system

    Don't go to the forums for a week and then discover the sign on process has changed - HAVE TO use a community sign on now - wonder what happened to the push for SSO.
    OK so register for a community sign on, not a problem I'll use the userid and password I always used to logon with, work with no problem then enter the activation code etc then WHAT's THIS
    Choose a screen name and give us your email address again, no problem I'll use my community logon id for a screen name and obviously my email is still the same because you just sent me an activation code, WHAT'S THIS
    That email address is already assigned - OF COURSE IT IS, IT'S MINE.
    Now no way to get into forums because every time you try to do it you are presented with the **bleep** screen name form
    OK I have another email address I'll use that, WHAT'S THIS email address is OK but presumably there's something wrong with my screen name Guess Screen Name CANNOT BE THE SAME as logon id, doesn't tell you that though.
    OK I'll make up something else just so I can get here and post this rant.
    THIS IS **bleep**
    I now have I believe 5 separate logons in the Verizon system.  Why do I have to have a separate logon to get to the forums after happily using my verizon id for 6 months?
    Interesting that the system inserts **bleep** for the word stu**d

    Restart machine
    Clear cache and it started working again.
    Something in the cache appeared to be determining that I was a VZ wirelss customer and therefore HAD to use a community userid to access the forums - that is it would not allow me the option to select either my VZ id OR a community id.
    Think it was to do with some window that comes up prior to the main VZ window when entering www.verizon.com.  Window seems to ask whether you are a Wireless, residential or business customer with a sign in prompt under wireless.  I think I may have signed in there and that is was screwed it up.

  • Addled Brain- which direction to go in setting up a t-shirt e-commerce site.Please help wise people!

    Hello,
    I have a little experience from 10 years ago building web sites, but things have changed a lot (but i am very good at teaching myself).  Can anyone advise me on the way to go?
    I want to create a t-shirt e-commerce site and have no money to pay anyone to make the site (maybe when the business is flying i will, but for now) - i am designing it myself and have all the design elements done, but do not know the best way to implement it given all the technologies out there; and do not want to go one way, to find out my efforts were wasted much later.  Here's my thinking...
    The main site contains the t-shirts.  When a user clicks on a picture it takes them to a 't shirt options' page where they can configure the design (put the design on the pocket, the back or the front in the center etc).  I was going to create check boxes for them to do this which when clicked, will change the picture to show them how it looks.  This means i will create picture for every possible check box option and load that into the 'this is what you t shirt looks like' space (easy enough and i can do that i think).  I will do that for every t-shirt on the main page.
    But I was thinking, could I just have a plane t-shirt in the 'this is what you t shirt looks like' space and using a picture of the design,  just reposition it and resize it using (and this is where my knoweldge is small at the moment) jqeury or some other language, or even CSS and divs?  What would be the best appraoch?  This way i would only have to create the design and the blank T-shirt and use code to position it to represent the final product.  Would it better to use a CMS such a Joomla to do this (this seems very complicated)?  Before i go any further than the design i thought i would ask you clever people.
    Thanks if you got this far...
    Conundrum part 2:
    The user will then click proceed to checkout where i will use a shopping cart system (probably Zen cart because that is on the hosting company's server that intend to use (unless suggested otherwise)).  I will need each version of the t-shirt to have a unique product ID that relates to a database that contains pricing options and this will be sent to the 'zen cart' and that will process the transaction.  Is my understanding correct?
    Many thanks for any suggestions.  Learnign one or two  things (CSS and DW) is OK, learning 5 things at once is making my head hurt! I have become confused

    Zen cart is free.  And you get what you pay for -- software that is hard to work with, not very good, poorly supported and has many security vulnerabilities which is why hackers love to exploit it. 
    Get a real shopping cart. Money well spent.  Building one yourself is risky and requires expert skill with server-security, data encryption, PHP, MySql, HTML, CSS, JavaScript, PCI compliance, SSL certificates, etc...   You'll drive yourself crazy trying to learn everything you don't know.  
    UltraCart is easy to set-up and they have a free 30 day trial so you can test before you decide.  There are many PCI compliant commercial carts you can use.   If you have a merchant bank account, start with your bank to find out which gateways and processors they require you to use.  That will narrow your search to carts that work with your payment gateway.
    As for your site, keep it simple, semantic, user friendly and responsive.
    Nancy O.

  • I am getting messages that I can't download and read .pdf files since I have the wrong Adobe reader. I know about their security disasters of course, but I downloaded the latest version of Adobe Reader from the Adobe web site and I have other ,pdf file re

    I am getting messages that I can't download and read .pdf files since I have the wrong Adobe reader. I know about their security disasters of course, but I downloaded the latest version of Adobe Reader from the Adobe web site and I have other ,pdf file readers as well, and for some reason they won't work either. I have 5 computers running top end processors and RAM. By this I mean I have one, this one which I am using that has an AMD Phenom Black 3.2 Quad-core with 8 GBs of Corsair top DDR2 RAM, my other two AMD have either an Athlon II triple core with 4 GBs of DDR2 Corsair RAM, one with the Phenom X4 965 3.4 GHz Quad-core with 8 GBs of their best DDR2 RAM, and two Intels with the i7 920 Processors using the triple channel 1366 socket processors and one with 8 GBs of low latency DDR3 RAM and the other with 4 GBs of the same RAM. I am getting the message on this one, which has a fresh install of XP Pro X64 operating system, as do the other 4 as well. I have run Avast Business Pro Anti-virus on this one, which I am getting the message on with a single result which I deleted, and also both Spybot Search and Destroy, which came back clean as well as Malwarebytes Antimalware, which got a lot of tracing cookies now removed, and SuperAntiSpware which also found a few cookies also now deleted. Can you tell me what I need to do to get these files to show as .pdf files rather than as a clean blank page. One other issue is that I wish to know how to turn off my downloads so they are saved and Mozilla will give me the option of returning them instead of me losing them all together as it does now. Thanks for your assistance. If there is another Adobe reader I should download and install, could you provide me with the link to it? I appreciate your assistance here
    == When I download and try to read a .pdf file and when I am asked to turn off all Firefox files and if I do, I lose them since I need to know how to save them without rebooting my computer.

    Brilliant! Problem solved! Thanks so much.

  • Can only connect to HTTPS (secure) sites and can't connect to HTTP sites

    In short I CAN ONLY connect to HTTPS sites, meaning secure.
    I've narrowed this down to an issue regrading my mac book pro and the wireless router.
    Router:
    - not sure of the make model
    - other computers CAN connect to this router and go online
    My Mac:
    - Mac Book Pro
    - OS X 10.6
    - I can connect to other wireless networks just fine
    - I can surf the web for about 10 minutes or so then it blocks ALL http traffic
    and i'm only allowed to https sites
    going to a http site results in a "page is taking to long to respond"
    please anything?

    The router is a Verizon MI424WR
    hope that helps, but i doubt it will...
    just to also clairfy http sites either go really slow then time out only never to come back, https are blazing fast

  • How can I find out the server port for a secured FTP site and creating a FTP Connection Manager

    I have to create a FTP Task to go out and get the files that our 3rd party vendor will be dropping on a secured FTP site. I have all the credentials to access that Secured FTP Site and have successfully done so through FileZilla.
    Now I need to set-up a FTP Task to go out and get their files and in so doing create a FTP Connection Manager. Is there any way I can determine the
    Server Port number from the Secured FTP site? I let it default to 21 and tried the Test Connect and it failed.
    Thanks for your review and am hopeful for a reply.

    Hi ITBobbyP,
    SSIS has a built in FTP task, while this only works for the FTP protocol, it doesn’t support SFTP. But there are some free clients like WinSCP and
    SSIS SFTP Task Control Flow Component
    available in the CodePlex which can invoked from SSIS.
    References:
    SSIS SFTP Task Control Flow Component approach
    WinSCP approach
    Thanks,
    Katherine Xiong
    Katherine Xiong
    TechNet Community Support

  • I downloaded norton internet security and it says I need firefox 4 to opperate correctly. I went to your site and downloaded lateset version and Norton still doesn't work . How do I get version 4

    I downloaded norton internet security and it says I need firefox 4 to opperate correctly. I went to your site and downloaded lateset version and Norton still doesn't work . How do I get version 4 so that my computer and I are protected?

    How can I go back to version 3? Thanx.

  • I am trying to access an https site and am getting a "This connection is untrusted" message. I am willing to bypass, but when I click the Add Exception button and then try to click the Confirm Security Exception button, nothing happens.

    I am trying to access an https site and am getting a "This connection is untrusted" message. I am willing to bypass, but when I click the Add Exception button and then try to click the Confirm Security Exception button, nothing happens.

    unfortunately the do_not_trust certificates might be a sign of unwanted software present on your pc that is intercepting secure network traffic. please go into the system control panel and uninstall programs like BrowserSafeguard, BrowserSafe, SafeGuard or other software that sounds suspicious and didn't get installed by you intentionally.
    <br><sub>reference: https://support.mozilla.org/en-US/questions/982532#answer-520145</sub>
    afterwards, run a full scan of your system with different security tools like the [http://www.malwarebytes.org/products/malwarebytes_free free version of malwarebytes] & [http://www.bleepingcomputer.com/download/adwcleaner/ adwcleaner].
    [[Troubleshoot Firefox issues caused by malware]]

  • Issues with certian sites and face book games since last security update

    After installing the latest security update on Friday 9/10/11, I'm unable to play certain facebook games, and twitter is no accessable. I get a blank screen, and a message that unable to connect with server. I can reach other sites, and use other facebook applications.

    Hello Tooky,
    I know it has been a while since you posted this topic on the Discussions board, but I am experiencing the same problem with the Safari browser. I have noticed that web ads have motion as well, and I am not sure whether this is intentional or an error.
    However, I did discover something. I reinstalled Quicktime 6 (I had been running QT 7) and the motion in the web ads stopped. Then, just to test this out, I upgraded to QT 7 again, and the motion in the web ads returned. I think it has something to do with QT 7.
    I am running 10.3.9, and I don't know whether people are experiencing this issue in 10.4. You mentioned in your posting that this issue has been discussed--is there any way you could direct me to one of the discussions? Have you discovered a workaround? I'm having trouble finding other threads on this topic.
    Thank you very much, and take care.
    Chris
    eMac   Mac OS X (10.3.9)  

  • Remote Sites w/VLANs and Security

    Attached I have a high level overview visio of what I'm trying to accomplish. Basically, I need to setup VLANs for both company and public traffic at remote sites seperated by PTP T1's. Company VLANs need to access other Company VLANs and the Internet, and Public VLANs only need to access the internet out the CheckPoint firewall.
    I'm assuming that ACL's would be needed to control what VLANs can see other VLANs, along with a routing protocol like EIGRP...but my main concern is ACL hell because I will be dealing with a lot of remote sites and a lot of company VLAN subnets.
    Also, my boss is worried about security in regards to the public network and he doesn't think that you can easily prevent the public network from accessing all the other company networks and still letting them get to the internet without extending the VLANs accross the T1's and all the way up to the CheckPoint Firewall.
    Any help and suggestions would be greatly appreciated.
    Thanks in advance,
    Scott

    So essentially I could have one ACL that encompasses the entire public network like 10.0.0.0 0.255.255.255 on each router and do the same for the corporate network to minimize the configurations needed.
    If I create ACLs denying anything with a source of the public network and destination of the corporate network, then allow all other traffic it should be sufficient correct? Also, I only need to put these ACLs on the interfaces closest to the source right? Not on every router on the network.
    Thanks again for taking the time to respond.
    Scott

  • I would like to import Security Trusted Sites and Popup Settings from Internet Explorer

    We are setting Firefox up on our Resource Room Computers and do not want to re-enter trusted sites and popup settings. How can I import them?

    Please help me get rid of this Pop up, it is driving me mad.  I tried  to access the forum on your address BUT the Conduit sight would not allow.
    Please can anyone help.
    Lorry M
    Date: Tue, 11 Mar 2014 13:08:12 -0700
    From: [email protected]
    To: <removed personal infomration>
    Subject: Re: I would like to remove an annoying popup from Adobe Flash Player everytime I access the Internet and I would like to remove an annoying popup from Adobe Flash Player everytime I access the Internet and
        Re: I would like to remove an annoying popup from Adobe Flash Player everytime I access the Internet and
        created by m_vargas in Using Flash Player - View the full discussion
    Hello,
    Flash Player does not display pop-ups.  If you are experiencing this behaviour you most likely have malware installed on your system.  You'll want to scan your system with anti-malwareand  anti-virus software.
    Maria
    Please note that the Adobe Forums do not accept email attachments. If you want to embed a screen image in your message please visit the thread in the forum to embed the image at http://forums.adobe.com/message/6200618#6200618
    Replies to this message go to everyone subscribed to this thread, not directly to the person who posted the message. To post a reply, either reply to this email or visit the message page: Re: I would like to remove an annoying popup from Adobe Flash Player everytime I access the Internet and
    To unsubscribe from this thread, please visit the message page at Re: I would like to remove an annoying popup from Adobe Flash Player everytime I access the Internet and. In the Actions box on the right, click the Stop Email Notifications link.
               Start a new discussion in Using Flash Player at Adobe Community
      For more information about maintaining your forum email notifications please go to http://forums.adobe.com/thread/416458?tstart=0.
    removed personal email address

  • Every since the June 22 security update, I get Mozilla Firefox (not responding) at any page I go to. Have to sit and wait several minutes for it to load each page. Getting all kinds of errors in arsing values. Declartion dropped. Etc.

    Warning: Expected declaration but found '*'. Skipped to next declaration.
    Source File: http://support.mozilla.com/media/css/questions-min.css?build=93872dd
    Line: 1
    Warning: Unknown property 'zoom'. Declaration dropped.
    Source File: http://support.mozilla.com/media/css/questions-min.css?build=93872dd
    Line: 1
    Warning: Error in parsing value for 'display'. Declaration dropped.
    Source File: http://support.mozilla.com/en-US/questions/new?product=beta
    Line: 0
    Warning: Unknown property '-moz-opacity'. Declaration dropped.
    Source File: http://support.mozilla.com/en-US/questions/new?product=beta
    Line: 0
    Warning: Error in parsing value for 'background-image'. Declaration dropped.
    Source File: http://support.mozilla.com/en-US/questions/new?product=beta
    Line: 0
    Just a few of the types of errors collected.
    It is getting to be a pain to have to sit and wait until it is responding again. At that point the cursor is locked on to what ever it is sitting over. You have to click on it to release it.
    Anyone have any ideas.

    Glad it is fixed. Thanks for posting back, (even if we are not sure exactly what happened).

  • Can Someone help me re: Building E -commerce site

    Hi
    I need to build a simple e -commerce site for an assignment. I want it to containg javabeans(to provide dynamic features) , sql database access and things like login/password user sections all all the other usual e - commerce stuff. Its going to be a simple site so not going to go over complex.
    Can someone please recommend me a good book from where I can be helped in building e commerce sites using java/jsp(im not very experienced with java) and if possible some advice as to where I should start etc?
    many thanks

    I need to build a simple e -commerce site for an
    assignment. I want it to containg javabeans(to
    provide dynamic features) , sql database access and
    things like login/password user sections all all the
    other usual e - commerce stuff. Its going to be a
    simple site so not going to go over complex.How experienced are you with the non-Java technologies? SQL and relational databases, security, HTTP/HTTPS, HTML, programming in general, object-oriented programming in particular?
    Could be challenging project for your first go at Java.
    Can someone please recommend me a good book from
    where I can be helped in building e commerce sites
    using java/jsp(im not very experienced with java) and
    if possible some advice as to where I should start
    etc?It's not an e-commerce book, but I'd say that Hans Bergsten's JSP book from O'Reilly would introduce you to enough technology to have a chance at starting this.
    %

  • MS Access, SharePoint and Security

    Let's say I sign up for Office 365.
    I use the SharePoint Site that comes with it to house my MS Access Lists and my compiled database *.accmde file.
    Can I set up a separate sub-site with only admin access to house a list of userID's and passwords so that when the user runs the database, it looks up this list and identifies the user, type of user, and which filter for the data in the full access sites.
    If that works, then I would also want to put the data in a limited sub-site and have the accmde file retrieve that data behind the scenes. I would like to limit accidental access to the data if at all possible.
    Any suggestions on how to design the tool for this?
    Frank

    Hi FrankHayAlexcander
    It seems you have the following questions about hosting Access data on Office 365
    Can Access connect to multiple SharePoint sub-site?
    Can you store User info in one sub-site to control what data the user sees?
    Can you hide these sub-sites so that users can't accidentally see this data?
    The short answer is that I'm not sure that what you are trying to do is even possible in a Web database published to SharePoint, and certainly would be very difficult in a traditional database.
    If you create a Web database in Access 2010 and publish it to SharePoint, then it is limited to the tables / SharePoint Lists in that sub-site.
    In this case the credentials of the user are passed to SharePoint to retrieve data. This means that to read the list the user would have to have permissions and so they could go out the site directly and see the same data.
    Using SharePoint permissions you could control what the user can see, but Access isn't going to be able to add much to that.
    If you create a traditional database, then you can link to lists in multiple SharePoint site as well as other providers like SQL, and Excel.
    When you created the link table here you have the option to store the credentials with the linked table.
    If you do not store the credentials the user will be prompted for the credentials to use.
    You could store the credentials for an Admin user when you link the table, but the problem is that if a user opens your database in the full version of Access can get to the linked tables, they will be able to see all of the data anyway.
    When it comes to security, the best answer is always to secure the data using the native features of the data store such as SharePoint, SQL, etc.
    Best Regards,
    Nathan Ost
    Microsoft Online Community Support
    Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • I am having an issue with an IBM site and it was suggested by customer service that I need to install version 3 of Firefox. I cannot find a site to do this.

    I need to download a copy of FireFox 3.o to be able to post updates in an IBM repository. The current 4.0 version doesn't allow me to post or open files in this repository.

    If you just need it for that one site, I believe a better option than replacing Firefox 4 is to install the portable version of Firefox 3 on your hard drive. You can use the portable version for the IBM site and Firefox 4 for other sites. You can get the portable version from http://portableapps.com/apps/internet/firefox_portable - Firefox 3 is listed in the legacy versions section.
    It is best not to use Firefox 3 for all browsing as it is no longer supported with security updates.

Maybe you are looking for

  • I can't sync music to my iPhone since I updated itunes

    I have always sync my iPhone 4 to my MacBookPro with no problem. Since I updated itunes is not possible. When I connect my iphone, it appears on itunes, recognizing the device and even runs the sync process but when I unplugged the iphoneI still have

  • How can I reorder pictures in slideshow that are brought in from Aperture?

    I am bringing in about 100 photos from Aperture. When I bring them in to iWeb they re-sort to be according to file name as opposed to the time the photo was taken (I am merging my photos with photos from a friend's camera taken of the same event, so

  • Connect a SPA112 to SPA232D

    Hello, I heard I could connect a SPA112 to SPA232D. Analog line ---> SPA112 ---> network ---> SPA232D ---> PTSN Can this be done via the web interface or does this require deeper command sets? Thanks,

  • Schedule job...

    i schedule a job using SYS.DBMS_JOB.SUBMIT for every 2 hours... its execution slot is 12PM and our DB is going down between 10PM to 1AM once the DB is up, the job will automatically stat for the next interval ie @2AM?

  • Contact Photos in Texting iOS 7

    In iOS 7, how can we see the other persons contact photo when we text?