How secure is this?

Ok, my program is designed to append a few strings representing credit card details, encrypting, and storing in mysql.
the encryption details are:
iterations: 19
8byte salt value
encryption type = PBEWithMD5AndDES
the key itself is stored in mysql, and is an md5 copy of my clients password. When data is put into the database, this key is grabbed from mysql, however for my client to view the cc details, they need to enter their password in a non-md5 format. My program will then convert this to md5 to produce the same key as is used to put info in the database.
How secure does this sound?

I know this but i am stuck here. My situation is: i
am a host, my clients have online shops, where they
sometimes want to store the customers CC details. my
clients log in to their admin using their username
and password, and i keep a copy of their md5 password
in my database, and obviously my login script turn
their password into md5 to check against the
database.
But when a customer orders something from my client,
a php script gives me the clients userid,Wide open! Based on this, any user id for any client will do!
so i can
check against the data in teh database and know where
to put the encrypted data. It would be insecure for
the php script to hold information about theclients
password.
Also, how many bits would my algorithm be?I once worked for a big bank that hired security consultants to look at security weaknesses. You should do the same.

Similar Messages

  • How secure is this transfer protocol?

    Is it just open on the cloud? Can I encrypt it? Can it be accessed by others who don't have the direct link?

    Hi Elizabeth,
    Please see this document about the levels of security employed by the Acrobat.com online services: Security for Acrobat.com online services | Adobe. I hope it helps put your mind at ease about the safety of the files you send via Adobe Send.
    Your files can only be accessed by those who have the link to it (whether you send a private invitation, or create an anonymous link and send that via email).
    If you have Acrobat, you can take the additional step of password protecting your PDF, so that only the folks given the password can open your documents. If you don't have Acrobat, you're welcome to try it for free for 30 days—see http://www.adobe.com/products/acrobat.html for more information.
    Please let us know if you have additional questions.
    Best,
    Sara

  • How secure is this setup

    My setup is as follows
    Qwest actiontec gt7100-wg dsl modem set to bridging mode attached by Ethernet cable to
    Time Capsule set to PPPoE
    I am assuming that the TC is doing NAT as it is handing out IP addresses in the 10.0.1.2 range
    The TC is password protected using WPA2
    Is there anything else I should be doing????
    Thanks in advance

    Your setup is just fine.
    With WPA2 Personal security enabled, which is the strongest encryption you can use for home use, you are in good shape there.
    DHCP is the process of assigning IP addresses to devices on the local network and your Time Capsule is doing this as you have it configured.
    The NAT firewall built into the Time Capsule will do an excellent job of shielding your private network from the Internet, so you are in good shape there as well.

  • How secure is this site

    Someone else is already in this message

    Start Firefox in <u>[[Safe Mode]]</u> to check if one of the extensions or if hardware acceleration is causing the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > Appearance/Themes).
    *Don't make any changes on the Safe mode start window.
    *https://support.mozilla.org/kb/Safe+Mode
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes

  • How secure is an encrypted pdf file?

    I am using Acrobat XI Pro => Require a password to open document => use a password that is 'Best' with the 4 gray rectangles on the right lighting up green => Compatibility: Acrobat X and later, Encryption Level: 256-AES
    In other words, the above is the strongest security that Acrobat XI Pro has to offer by way of encryption. But just how secure is this strongest security? Any of the experts here care to give a lay person a feel for the level of security in case the encrypted pdf file gets in the wrong hands?

    It would be very hard (take a very long average amount of time) to crack the security with that password and encryption level, but both the "document open" and "change security" passwords should have the same high level of strength since both can be used to open the document. Be sure to use passwords that aren't susceptible to dictionary attacks.
    Check out this site: https://www.grc.com/haystack.htm
    but read the background information so you know what it's showing.

  • How secure is Adobe for gathering info from electronic forms

    I am considering using Adobe.com to gather responses from an electronic registration form. The form response will contain credit card info. How secure is this cloud?

    All of the the communications with the server are protected with SSL (https). This FAQ explains in more detail:
    http://forums.adobe.com/docs/DOC-1384
    Randy

  • How secure is internet sharing?

    I apologize if this is a stupid question...I am new to sharing and not very tech savvy...just know enough to do what I need to. I recently discovered I can share my internet connection thru airport so I can connect my iPod Touch and use it online and I read the steps needed to do so.
    My question is: how secure is this If set it up with the 128-Bit and 13 letter password? I'd like to set it up on my iMac at work, but am afraid of others being able to get on or access it, or my iPod Touch.
    I appreciate your thoughts on this. Thanks so much!

    so long as you don't use the WEP (40 bit) setup, should be ok...
    now anything that's wireless, someone could crack if they have enough time & data packets to scan for the keys. but they would be set back to 0 once the password is changed. also, I wouldn't be doing anything at work that you wouldn't want anyone else to see anyway.

  • How secure are VS2010 controls - grid using sql

    I have an API from a vendor that is using a macro that was not encrypted that I used as a parm which was intercepted and changed by the users with the inspect element feature in a browsers.
    Now I'm changing the app to avoid taking in any parms and writing it in server side code using a datagrid with an embedded data connection and sql statement.       The plan is to publish this as a web application only placing
    the source on the server.   How secure is this method? Is there anything I need to look out for or avoid doing?   The material displayed on this page is sensitive information therefore I need it to be as secure as possible.
    Thanks!

    Hi kindnesshelps,
    Based on your description, it seems that it is not the correct forum for this issue, since this forum is to discuss:
    Visual Studio WPF/SL Designer, Visual Studio Guidance Automation Toolkit, Developer Documentation and Help System, and Visual Studio Editor.
    To make this issue clearly, would you mind letting us know more information about this issue? Which language are you using? Which kind of app are you developing? Which VS IDE version do you have?
    >> The plan is to publish this as a web application only placing the source on the server.
    You said that “publish this as a web app”, do you mean that this issue is related to the Web app?
    If this issue is related to web app, you could ask this question in the ASP.NET forum:
    http://forums.asp.net. If then, you could get an answer more quickly and professional. Thanks for your cooperation.
    Best Regards,
    Jack
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • When I try to download the latest version of iTunes on my iPod Classic I get the message that "iTunes has an invalid signature" and that "Content was blocked because it was not signed by a valid security certificate.  Anyone know how to fix this?

    When I try to download the latest version of iTunes from apple.com, I get the message "Content was blocked because it was not signed by a valid security certificate."When I open iTunes and try to download the latest version there, I get the message "iTunes has an invalid signature.  The download has been removed."  I have also gotten an Internet Script Error stating that an error has occured in Line 0, Char O and that "Access is denied to images.apple.com/global/scripts/lib/iepngfix.htc."  This problem has never occurred with earlier versions of ITunes.  Anyone know how to fix this problem? 

    Are you downloading iTunes form an Apple website or somewhere else? If the answer is somewhere else, try downloading it from Apple. Click on iTunes in the black menu bar above and go from there.
    Let us know what happens.

  • Can't update iOS 8 on my iPhone5 through iTunes on Windows 8 (error 3004, 3194). Updated host file, opened port 80, 443; turned off security system and firewall, etc. But nothing works. How to solve this problem?

    Can't update iOS 8 on my iPhone5 through iTunes on Windows 8 (error 3004, 3194). Updated host file, opened port 80, 443; turned off security system and firewall, etc. But nothing works. How to solve this problem?

    Hi the_mad_movies,
    It seems like this article will be the best option for addressing this issue:
    Error 3194, Error 17, or "This device isn't eligible for the requested build"
    http://support.apple.com/kb/ts4451
    Thanks for coming to the Apple Support Communities!
    Cheers,
    Braden

  • Exception TYpeError:netscape security privilegemanager is unidentified,pls let me know how to fix this error

    I am trying to launch Db2 setup installation but error is coming -Exception TYpeError:netscape security privilegemanager is unidentified.
    Please let me know how to fix this.
    Thank you
    Nazia

    hello, privilegemanager is deprecated since firefox 12 - please contact ibm's support if you are having problems installing their product.

  • HOW DO I GET RID OF THIS MESSAGE - ADD SECURITY EXCEPTION you are about to over ride how Thunderbird identifies this site. Location pop.shaw.ca.110 no e-mail

    I KEEP GETTING A BOX WITH THIS MESSAGE - ADD SECURITY EXCEPTION
    you are about to over ride how Thunderbird identifies this site
    LOCATION: pop.shaw.ca.110
    then it asks for a security certificate
    I DO NOT KNOW HOW TO FIX OR BETTER YET GET RID OF THIS MESSAGE

    You're supposed to take a screenshot. The link has instructions about how to do that.
    Then attach the resulting image to your post by using the 'Browse' button right above the 'Post Reply' button.

  • HT201363 Hello I forgot my Security question of my Apple ID ? I don't kow what should I do and how to solve this problem ? could you please help  ?

    Hello I forgot my Security question of my Apple ID ? I don't kow what should I do and how to solve this problem ? could you please help  ?

    You need to ask Apple to reset your security questions; ways of contacting them include phoning AppleCare and asking for the Account Security team, clicking here and picking a method for your country, and filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (104569)

  • HT5312 I forget my answer of two security questions, there is a typo error in rescue email address. How to resolve this so that I can use my Apple ID for online shopping?

    I forget my answer of two security questions, there is a typo error in rescue email address. How to resolve this so that I can use my Apple ID for online shopping?

    You won't be able to change your rescue email address until you can answer your questions, you will need to contact Support in your country to get the questions reset.
    Contacting Apple about account security : http://support.apple.com/kb/HT5699
    When they've been reset you can then use the steps half-way down the HT5312 page that you posted from to correct your rescue email address for potential future use

  • HT1918 I'm trying to update my credit card, but it won't let me input the security code.  Does anyone know how to solve this problem?

    I'm trying to update my credit card in ITunes, but it won't let me input the security code.  Does anyone know how to solve this problem?

    Could you give me more details on how it would let you put in the CVV?

Maybe you are looking for