Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

X-Payments 1.0 beta5 announcement

 
Closed Thread
   X-Cart forums > News and Announcements
 
Thread Tools
  #211  
Old 07-02-2010, 06:37 PM
 
dmr8448 dmr8448 is offline
 

Senior Member
  
Join Date: Jun 2003
Posts: 123
 

Default Re: X-Payments 1.0 beta5 announcement

I just did a fresh install of X-cart 4.3.2 and I am trying to do a test install of X-Payments and I get the following reason for the install failing:

Web Location settingsweb :<Missing parameter> (this shows as missing even though I have it filled in correctly in the config file)


Critical dependenciespdo PHP extension:disabledRequired: enabledpdo_mysql PHP extension:disabledRequired: enabled
What does this mean and how would we enable it?

Thanks
David
__________________
Version 4.3.2
  #212  
Old 07-02-2010, 06:45 PM
 
kevinrm kevinrm is offline
 

X-Wizard
  
Join Date: Aug 2003
Posts: 1,003
 

Default Re: X-Payments 1.0 beta5 announcement

It pops up another screen where you enter your credit card info. You can't really tell that you are taken out of x-cart, it looks pretty seamless.

My problem with it so far is skinning it. The default skin is "okay" but generic. There is a xp-skin-generator.php file that will supposedly generate a skin that matches your site. I can generate the skin, but I can't get it to work save my life. The supplied instructions are lacking, I've had more problems with this part than any other area of x-payments.

I have mine installed and ready to go. I don't have x-payments "live" at the moment because I don't have the skin thing working, but should I have to go "live", I can do so. Just waiting to be forced into it.


Quote:
Originally Posted by dmr8448
Does any one have an example of how the x-payments works during the checkout process of x-cart. So if someone selects "credit card" as there payment option...what happens.

Is the user then taken to the x-payments system and are they totally out of x-cart then.

Will this still look seamless to the end user that is shopping on the site?
__________________
X-Cart 5.4.1.39 Live
PHP 7.4.33
5.5.5-10.3.38-MariaDB MariaDB
Apache 2.4
CENTOS 7.8 64Bit Single Quad-Core E3-1241v3 3.4Ghz 8M 1600 w/ HT
32GB RAM 2x 512GB Samsung 850 Pro SSD RAID 1
  #213  
Old 07-02-2010, 06:51 PM
 
kevinrm kevinrm is offline
 

X-Wizard
  
Join Date: Aug 2003
Posts: 1,003
 

Default Re: X-Payments 1.0 beta5 announcement

I made a completely new thread for discussing installation in the "x-cart add ons" area of the forum, seems like that would be a more appropriate area to post in but no one seems to care so I guess I'll address this here.

First, you are running PHP 5.3.x, right? If that is the case, then you should be able to go into your control panel and adjust the PHP settings. You may have to do it with unix commands. Or, you may have to have an admin do that, depending on your situation. Seems like mine just worked when I had PHP 5.3.2 installed.

Another area that was confusing was using the " " in the config file - you need to use the quotes for most of the settings.


Quote:
Originally Posted by dmr8448
I just did a fresh install of X-cart 4.3.2 and I am trying to do a test install of X-Payments and I get the following reason for the install failing:

Web Location settingsweb :<Missing parameter> (this shows as missing even though I have it filled in correctly in the config file)


Critical dependenciespdo PHP extension:disabledRequired: enabledpdo_mysql PHP extension:disabledRequired: enabled
What does this mean and how would we enable it?

Thanks
David
__________________
X-Cart 5.4.1.39 Live
PHP 7.4.33
5.5.5-10.3.38-MariaDB MariaDB
Apache 2.4
CENTOS 7.8 64Bit Single Quad-Core E3-1241v3 3.4Ghz 8M 1600 w/ HT
32GB RAM 2x 512GB Samsung 850 Pro SSD RAID 1
  #214  
Old 07-02-2010, 07:14 PM
 
dmr8448 dmr8448 is offline
 

Senior Member
  
Join Date: Jun 2003
Posts: 123
 

Default Re: X-Payments 1.0 beta5 announcement

Quote:
Originally Posted by kevinrm
I made a completely new thread for discussing installation in the "x-cart add ons" area of the forum, seems like that would be a more appropriate area to post in but no one seems to care so I guess I'll address this here.

First, you are running PHP 5.3.x, right? If that is the case, then you should be able to go into your control panel and adjust the PHP settings. You may have to do it with unix commands. Or, you may have to have an admin do that, depending on your situation. Seems like mine just worked when I had PHP 5.3.2 installed.

Another area that was confusing was using the " " in the config file - you need to use the quotes for most of the settings.

I am running 5.3.2 and my host says that the PDO items are enabled, but the install script shows them as disabled. IS there a way for me to check if they are enabled? Will that show in a phpinfo.php file?
__________________
Version 4.3.2
  #215  
Old 07-02-2010, 08:07 PM
  BCSE's Avatar 
BCSE BCSE is offline
 

X-Guru
  
Join Date: Apr 2003
Location: Ohio - bcsengineering.com
Posts: 3,066
 

Default Re: X-Payments 1.0 beta5 announcement

There appears to be some difference of opinion with respect to PCI compliance. BCS Engineering always suggests that you consult with the bank that manages your CC accounts to ensure that the direction you take is in sync with their understanding of security in the CC environment.

BCS Engineering is taking a very conservative view on the PCI compliance interpretation. When fines of $100,000 or more are involved we would much rather take the more security approach.

Each SAQ lists the eligibility items in section 2D, except for SAQ D which is meant for any Merchant system that doesn▓t fit into the other 3. We see the SAQ schedules as follows:

SAQ A √ Any Merchant that uses an offsite processor (Paypal, Authorize.net SIM, 2checkout) to handle credit card transactions.

SAQ B √ Any Merchant that uses paper receipts or dedicated standalone dialup or internet connected terminals.

SAQ C √ Any merchant that uses their general use PC to transmit credit card transactions. BCSE▓s interpretation is that this questionnaire covers systems like Quickbooks, other point of sale systems, or backoff accounting systems that run in a physical location. For example, a store front or office based system.

SAQ D - This is the catch-all if you don▓t fit into one of the other questionnaires.

We had an organization come to us in the middle of a hacking event; we rebuilt their site and took over hosting it. Their Bank has them filling out SAQ D every year. All indications from that Bank was that they should have been doing that all along. If you talk to the major hosting service providers about a PCI compliant environment they will lead you to the system that is suggested in SAQ D 2.2.1.

Separation of services is a basic security principle. You don▓t want a vulnerability in one service to allow a perpetrator to get into another service. We have helped too many customers through events where an out of date blog or content management system has allowed a hacker to get into a store. The whole point of PA-DSS compliance is to minimize the risk of a hacker getting into the front door, but that is a moot point if unpatched X-cart release 4.1 is also on the same server acting as an open back door. Even without the new PCI compliance rules, this is how we recommend running an ecommerce site. We▓ve just simply seen too many people get hacked and had CC stolen simply because either their X-cart wasn▓t patched or some other unrelated application wasn▓t patched.

BCSE Engineering is not a PCI compliance auditor and cannot even be one because we create web application software. What we presented in our document is what we feel to be a conservative and natural security progression for ecommerce sites. What would be really nice to see happen is if a certified PCI security auditor would make an online web presentation to the X-cart community to clear issues up.
__________________
Custom Development, Custom Coding and Pre-built modules for X-cart since 2002!

We support X-cart versions 3.x through 5.x!

Home of the famous Authorize.net DPM & CIM Modules, Reward Points Module, Point of Sale module, Speed Booster modules and more!


Over 200 X-cart Mods available & Thousands of Customizations Since 2002 - bcsengineering.com

Please E-Mail us for questions/support!
  #216  
Old 07-02-2010, 09:10 PM
  DogByteMan's Avatar 
DogByteMan DogByteMan is offline
 

X-Adept
  
Join Date: Mar 2003
Posts: 833
 

Default Re: X-Payments 1.0 beta5 announcement

Quote:
Originally Posted by BCSE
Separation of services is a basic security principle. You don▓t want a vulnerability in one service to allow a perpetrator to get into another service. We have helped too many customers through events where an out of date blog or content management system has allowed a hacker to get into a store. The whole point of PA-DSS compliance is to minimize the risk of a hacker getting into the front door, but that is a moot point if unpatched X-cart release 4.1 is also on the same server acting as an open back door. Even without the new PCI compliance rules, this is how we recommend running an ecommerce site. We▓ve just simply seen too many people get hacked and had CC stolen simply because either their X-cart wasn▓t patched or some other unrelated application wasn▓t patched.

Then I would assume you sure would not want to put a gold mine of X-Payments linked to X-Carts together on one server and call them as separate. One person gets careless, everyone on that X-Payments server goes down with them.
__________________
Dedicated Server provided by EWD Hosting
X-Cart version 4.1.12
PHP 5.3.2
MySQL server 5.0.87-community
Operation system Linux
Perl 5.008008
dogbytecomputer.com
  #217  
Old 07-03-2010, 01:16 AM
 
dmr8448 dmr8448 is offline
 

Senior Member
  
Join Date: Jun 2003
Posts: 123
 

Default Re: X-Payments 1.0 beta5 announcement

Quote:
Originally Posted by dmr8448
I am running 5.3.2 and my host says that the PDO items are enabled, but the install script shows them as disabled. IS there a way for me to check if they are enabled? Will that show in a phpinfo.php file?

My php.ini files shows

extension=pdo.so
extension=pdo_mysql.so

Does that mean these are enabled? Most host says they are enabled, but when I try and run the X-Payments install script it says these are disabled and will not let it install.
__________________
Version 4.3.2
  #218  
Old 07-03-2010, 06:28 AM
  cflsystems's Avatar 
cflsystems cflsystems is offline
 

Veteran
  
Join Date: Apr 2007
Posts: 14,191
 

Default Re: X-Payments 1.0 beta5 announcement

Quote:
Originally Posted by BCSE
Even without the new PCI compliance rules, this is how we recommend running an ecommerce site. We▓ve just simply seen too many people get hacked and had CC stolen simply because either their X-cart wasn▓t patched or some other unrelated application wasn▓t patched.

But the shared hosting is just that - many users on one server and if one of them gets hacked "simply because either their X-cart wasn▓t patched or some other unrelated application wasn▓t patched" it is possible all of them to get hacked. So where is the difference then? What makes you recommend X-Payments on a separate server but before X-Payments all of these carts shared space and resources and were collecting CC info, with some of them even saving that info in their database. I see your point of getting everything as secure as possible but do not see the reason for X-Payments being on a separate server. (not attacking you just looking for answers in that whole mess)
__________________
Steve Stoyanov
CFLSystems.com
Web Development

The following user thanks cflsystems for this useful post:
EN4U (07-03-2010)
  #219  
Old 07-03-2010, 09:25 AM
 
Asiaplay Asiaplay is offline
 

X-Wizard
  
Join Date: Oct 2005
Posts: 1,242
 

Default Re: X-Payments 1.0 beta5 announcement

lol - Only because that way they can charge outrageous prices for hosting X-Payments... crazy, but true...

Cheers - Asiaplay

PS: Germany did well tonight in world cup - 4:0 - wow!!!!!
__________________
X-Cart Gold version 4.1.9
(plus built in X-Cart bugs!)
  #220  
Old 07-03-2010, 09:30 AM
 
EN4U EN4U is offline
 

eXpert
  
Join Date: Feb 2008
Location: AZ
Posts: 379
 

Default Re: X-Payments 1.0 beta5 announcement

Here we talk just about payment mods...... etc.... What about the store itself and all of its mods. Do they all need to be upgraded? I know in my Miva store there were mods that needed updating, all free.. yet there were some. Also some code changes here and there.

This goes way beyond a payment setup to become PCI complaint. This is truly more of a mess than i think is even recognized.
__________________
Regards, Dan
X-Cart Gold Version 4.1.10

1 - One page checkout
2 - Image Generator
3 - CSDEO Pro
4 - Shop By Price
5 - Next - Previous
6 - On Sale
7 - Shop By Price

8 - Froogle & Google Base Feed
9 - Buy Together
10 - Customer Loyalty Points
11 - Customer Reward Points
Customer Reward Points Referral Add-on
12 - Product Reviews
13 - Other Custom Modifications
----------------------
http://www.townsqjewelry.com/
http://www.eroticnights4u.com/ <---- Adult Oriented - Toys
Closed Thread
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 09:16 PM.

   

 
X-Cart forums © 2001-2020