Tag Archive 'SSL'

How to Find Secure Shared Hosting

If you are looking to save money on building and managing a website, shared hosting may be the way to go.  Shared hosting is incredibly affordable these days, so much that you can have a personal or business website for just a couple of dollars a month.   What makes this arrangement so affordable?  With shared hosting, you are literally sharing disk space and various resources with other customers.  This allows the web hosting provider to rake in guaranteed profits while keeping expenses to a minimum.  Shared hosting is very economical but there are some drawbacks to this type of arrangement, mainly security.

The major issue with shared hosting has always been the same – the availability of security and the fact that this platform can only be so secure.  Without adequate protection, the web host’s server is vulnerable to a wide range of threats including DDoS attacks, malware infection and network intrusion.  You could also be exposed to attacks such as SQL injection, cross site scripting and even the malicious actions of your neighbors on the server.  When your hosting environment isn’t properly secured, you stand the risk of losing the most sensitive of information.

Security is definitely an issue in the shared hosting environment, one that could make the low cost an uneven trade.  The good thing is that several web hosting providers are aware of these vulnerabilities and they are taking the necessary approaches to deliver a secure service.  When looking for a company to host your site, we recommend keeping the following security considerations in mind.

Protection from Thy Neighbor

When assessing the security of a particular web host, you must not only analyze the protection offered against outside threats, but security that keeps you protected against other website owners on the server.  You never know who you’re sharing the server with, as they could be into dealing porn, distributing spam or malicious software.  A few of your next door neighbors just might be prolific computer hackers.  To keep yourself protected in this regard, you should make sure the provider doesn’t allow any unsolicited code to be executed or access to your directories.

Clean Code

One of the biggest threats to your website lies in the code used to build your applications.  When they are not properly scripted, intruders can use them as an entrance to your data and reap major havoc.  You can minimize the possibility of common website exploits by ensuring that the web hosting company offers the latest in development tools whether its PHP and MySQL or ASP and MS Access.  Most importantly, it is up to you to make sure you are coding your applications and web pages in a secure manner.

Security Features

There are also a number of features that will give you an idea of how secure a particular web hosting platform is.  This includes protection for the actual server such as software that defends against DDoS attacks and viruses as well firewalls and network intrusion systems to fend off hackers.  If your site is to involve online business transactions, you will also require SSL support to protect your customers’ credit card information.  When making sure all the vital security issues are addressed, you can better your chances of enjoying a smooth run in the shared hosting environment.

Category: Security Issues
Tags: , , , , , , , , , , , , ,
Posted on Tuesday, Jan 13, 2009
Trackback URI   Comments RSS

The Essentials of E-commerce

You may have been proficient at getting customers to buy products from your store in town, but online business is an entirely different game.  Similar to the traditional business, you must literally build your store yet take a different approach towards drawing in customers and accepting payments.  The essentials of e-commerce should go a long way in helping you succeed with your online business endeavors.

Building the Site

Obviously, creating your website is the first essential step.  There are several tools available to help with this process from simple web building programs to dynamic programming languages.  While a piece of cake for the experienced webmaster, this could present a huge challenge for someone who lacks web design skills.  In this case, you should strongly consider hiring a qualified designer to build your site.  A costly investment?  Perhaps, but look at it from this perspective – it will cost far less than paying the architecture and construction company to build the facility for a traditional storefront.

Collecting Payments

Whether you’re dealing in goods or services, you need a way for customers to select items and take them to checkout.  To accomplish this your e-commerce site will need a shopping cart.  A quality program will allow you to add different products and categories, add taxes and shipping options, accept payment in various methods and more.  When it comes to shopping carts you generally have to options: you can purchase a commercial product or go with an open-source solution.

Open-source shopping carts like osCommerce are widely available and may be offered at no additional cost with your web hosting package.  Such a program will provide all the features you need to set up an online storefront.  The disadvantage of open-source shopping cart is that some are not easy to customize and don’t cater to inexperienced users.  Additionally, stores created with open-source software tend to look very similar to one another.

Commercial solutions are generally easier to customize and offer more features.  This type of shopping cart will provide the uniqueness that allows you to standout from all the other store owners on the web.  The downside here is that a program like Miva Merchant carries a high-end price tag that ranges from hundreds to thousands of dollars.  You also need to make sure that your web host supports the software so it can be easily incorporated into your e-commerce platform.

Selecting a Payment Gateway

In addition to the shopping cart, you will require a payment gateway that enables credit card payments to be transferred to your banking account.  To accomplish this task you can either sign up for a merchant account or use a third-party payment processor.  Merchant accounts have setup fees, transaction fees and strict qualifications.  However, the transaction fees are lower than using a service such as PayPal.  In either instance, the overall cost are typically less when your monthly sales are over $1,000.  Keep in mind that you will also need to secure the payment environment and protect your online transactions.  The best way to ensure this security is with an encryption protocol known as SSL.  You may have to purchase a certificate with a merchant account while PayPal takes care of securing your transactions.

Bringing in Customers

After creating the site and setting up the store, it’s time to generate some traffic and sell your items.  There are many ways to go about this including advertising, getting your visitors to sign up for a newsletter, pay-per-click campaigns and specially crafted landing pages.  Succeeding with e-commere is no easy task, but when laying a solid foundation, you can give yourself a much better chance of making continuous sales.

Category: E-commerce
Tags: , , , , , , , , , ,
Posted on Monday, Jan 12, 2009
Trackback URI   Comments RSS

Keeping Your Profits Intact

Although thousands of new business websites are going up everyday, not everyone is succeeding with E-commerce.  Many people who lose out on sales and end up failing do so for two of the same reasons:  abandoned sales and charge backs.

Lost Sales

Today’s shopping cart applications offer numerous features.  However, all of them are designed to collect sensitive information from your customers.  This includes their contact information and credit card numbers among other details.  While this is a standard procedure of online shopping, one needs to consider the perspective of the new buyer.

After navigating your site, the visitor has come across a product they want to purchase.  They click on the checkout icon and proceed to enter the required information.  From there the customer is directed to your preferred payment gateway where they are forced input the same information again.  This results in lost or aborted sales as consumers are generally lazy and cautious about handing over their sensitive details.  Ideally, it would be great if your shopping cart could bypass all these requirements and take the customer straight to your gateway.  Unfortunately, there are a number of gateways, all of which require different variables.

So, how do you salvage the sale from here?  Log into the administrative section of your shopping cart, find out if you can track the abandoned sale and contact the potential customer via email.  Let the customer know that you have observed their attempt to place an order and ask if they had any trouble making a purchase.  Explain that you are willing to assistance with any problems they may have experienced.  By reaching out to the consumer on a personal level, there might be a chance of recovering the sale.  In a worse case scenario, you can at least find out if something in your ordering system isn’t functioning properly.  Everyone wants to feel like they are more than just another number.  Taking out the time to make contact and find out the problem might give them the confidence that you are worth doing business with.

The Dreaded Chargeback

Charge backs have been a nightmare for many E-commerce businesses.  You receive an order for one of your products, ship it out, and a week or so later there is a charge back.  This results in you shipping your goods for free, being forced to refund the customer and then pay a charge back fee.  One way to avoid this is to make sure your gateway offers some of type of protection against fraud and dishonest customers who purposely cause charge backs after receiving products.  While every charge back isn’t of a fraudulent nature, all can have a major impact on your pockets.

Conclusion

As the owner of an E-commerce business, you need to think like a prominent enterprise and focus on your bottom line.  If something is negatively affecting your profit, you need to make the proper adjustments to improve the service for customers and ultimately the longevity of your business.

Category: E-commerce
Tags: , , , , , , , ,
Posted on Wednesday, Dec 03, 2008
Trackback URI   Comments RSS

VeriSign Passes a Tremendous Milestone

Security is one issue that is on the mind of millions of website owners throughout the world.  It’s good to know that more people are paying attention to the risks and have taken the steps needed to secure their sites.  Earlier this year, VeriSign Inc., the leading online security and infrastructure company, reached a tremendous milestone with more than one million current SSL certificates.  Deployment of the one millionth active SSL (Secure Sockets Layer) certificate attributes to the solid security used by well over 90% of today’s Fortune 500 Companies and some of the largest banks in the world.

Chris Babel, senior vice president at VeriSign, notes that consumers need a greater level of assurance that the sites they visit online are safe to do business with.  The milestone of one million active SSL certificates demonstrates the firm’s presence in the industry.  Babel went on to state that VeriSign will continue to collaborate with its industry peers and help customers find most secure places for making purchases online.   Already responsible for securing more servers than any other internet security company, the VeriSign Secured Seal has become the most trusted of all on the web.

SSL certificates issued by VeriSign include VeriSign, GeoTrust and Thawte, all of which help to safeguard consumers against fraudulent websites by providing and validating information about the owner of the certificate. Consumers can learn the identity of the person they are dealing with and if the certificate holder is the legal owner of the domain name.  Most of all, these SSL certificates encrypt the customer’s personal information during internet transactions.   When a consumer visits a site equipped with such a certificate, their browser will display a padlock icon as well as HTTPS in the address bar.  This enables visitors to browse a web page with a greater level of confidence, helping them to feel comfortable about dealing with a legitimate site.

The most widely recognized of all, the VeriSign Secured Seal gives indication that a particular web page is protected with a brand of SSL certificate issued by VeriSign itself.  Throughout the world, this seal represents trust and security, one that has become a common fixture to validate leading online merchants, financial institutions and other prominent businesses on the internet.

A recent study conducted by TNS Research shows that 79% of online shoppers in the United States are familiar with VeriSign’s Secured Seal, trusting it more than other mark on the internet.  This seal is viewed well over 150 million time each day, thoroughly tested and proven to help boost online transactions by as much as 31%.  The study also reveals that the VeriSign Secured Seal can be found on more than 90,000 sites in over 140 countries across the globe.

Since the late 90s, VeriSign has been providing services for a reliable internet infrastructure to secure the huge world of networked computers.  Countless of times each day, its trusted SSL certificates and recognizable seals help businesses and consumers from worlds apart engage in secure E-commerce transactions with the utmost confidence.

Category: Security Issues
Tags: , , , , , , ,
Posted on Friday, Nov 21, 2008
Trackback URI   Comments RSS

Staggering Numbers on Website Vulnerabilities

According to a recent study by Scott + Scott, a law firm based in Connecticut, 85% of businesses in the U.S. have experienced some sort of data breach, a factor that places the personal information of millions of consumers at great risk.  To no surprise, most of the companies involved in the study were exploited over the web with the leading cause being insecure servers and applications.  These vulnerabilities are what result in the lost of bank account numbers, credit card details and Social Security numbers while putting billions of dollars in jeopardy. Although there are various security mechanisms available to limit these exploits, the typical components such as firewalls and intrusions detection systems simply aren’t enough.

Intruders are just as aware of the critical information that can be accessed through an application as the webmaster.  In many cases, their entrance and overall success is attributed to numerous factors.  Those conscious of the roaming threats typically monitor network perimeters with firewalls and intrusion detection systems.  However, these components actually encourage exploits as they are required to keep ports 80 and 443 open to support SSL and protect online transactions.  To an intruder, these ports are open doors that enable website attacks in a number of different ways.  Most network firewalls are configured to secure only the internal perimeter, leaving the company open to a wide range of attacks.  And while both intrusion prevention and detection systems are somewhat more effective, they don’t perform complete analysis of a packet’s contents.  Without an additional layer of security, a knowledgeable intruder can penetrate a web application with relative ease.

An organization dedicated to improving the security of web-based applications, the OWASP (Open Web Application Security Project) recently composed a list of 10 of the most common vulnerabilities in today’s applications.  The potential threats are associated with the following:

1. Cross site scripting

2. Server-side scripting errors

3. The execution of malicious code

4. Insecure direct object reference

5. Cross site request forgery

6. Improper error handling and data leakage

7. Penetration of authentication and session management

8. Vulnerable cryptographic storage

9. Insecure web communications

10. Failure to restrict write permissions and URL access

The WASC Web Application Security Consortium have validated the OWASP’s top five application vulnerabilities with the testing of 31,373 sites.  Additionally, the Gartner Group reports that 97% of more than 300 sites studied in a survey were found to be vulnerable to application attacks.  The same study also revealed that 75% of today’s web attacks occur at the application level.

The numbers indicate that most E-commerce sites are easy targets for an array of attacks.  While proper coding is the key to prevention, one of the best methods of defense against application exploits is a web application scanner.   This type of mechanism protects both applications and servers from intruders by crawling through the site and analyzing every piece of content.  Such products conduct various tests along with simulated application attacks throughout the scanning process.  If genuine security holes are detected, reports are made and detail the severity of each vulnerability.  Security experts recommend using a scanner that offers a technical, in depth explanation of each vulnerability detected along with appropriate suggestions for eradicating them.

Category: Security Issues
Tags: , , , , , , ,
Posted on Thursday, Nov 20, 2008
Trackback URI   Comments RSS

« Prev - Next »

Sponsored Links