Tuesday, August 05, 2008
web application security
A few months ago a friend of mine decided to start his own online business. It seemed like a good idea at the time. He had a lot of novelty items, nicknack's and gift items and was getting tired of selling them in his little shop and on Ebay, so he thought he would open up the online market for himself and if all went well, he was ready to close his shop and just sell online. Selling full time online would help him to stay at home with his son and still make enough money to support his family. He didn't have much capital, so after he started up his website and learned that he needed about $2000 to get some marketing going to drive business to his website, he came to me and I decided to invest in his business. I thought it was a sound investment, he gets his items for a really good price, and I really thought that he would do well. Anyway, neither of us really knew much about running a site, but we worked together and things finally started rolling. I really thought that we had this thing in the bag.
There was one thing that we really didn't account for. We did not know the PHP security on our website was no good. We thought we had everything taken care of and then we received a phone call telling us that our website was not as secure as we thought. We were informed that hackers tend to target shopping cards and online payment forms and that they have gotten really good at breaking through the standard security on these forms and that we needed to get a web application security system for our site. I looked more into this and found out that they were right. Hackers could be stealing our customers information without our knowledge, and then using behind their backs. It could take months even years to locate this problem and people would not even know who took their information.
I think it goes without saying that we purchased a web security application for our site, and now we can have piece of mind knowing that our secure forms are truly secure.
Posted by Rick at 12:33 PM