Spammers, Crackers, and Hackers are looking for ways to break into your system. They could send you something as simple as what looks like a complaint, only to find out that the attachment is a TROJAN. Their motive is simple...they want your credit card data base!
One of the most recent areas of concern is the hacking of the Merchant Accounts and the exploitation of the Merchant's Gateway Software and Shopping Carts. Hackers, using vulnerabilities like iis will access the Merchant server looking for credit cards and the file that contains a Merchants ID and password for his gateway. This gives the hackers the ability to log into the Merchants account and run credits to their cards. There are also gateways out there so insecure all you need to validate a credit card is the Merchant ID, which can be found on his credit card submission page. The script can be run from any IP in the world. The thousands of fraudulent validations can cost the Merchant tens of thousands of dollars in processing fees.
The solution to the gateway problems is to make sure your software must use a password to process a transaction. Also, make sure the software can run from only one locked down IP address. And lastly, make sure your site has all of the updates and patches to ALL software used at your site.
The Card Associations will require certain minimum security requirements. To comply and keep your Merchant account, it's best to begin shoring up security as soon as possible. The following links will give your IT staff the resources to lock down your site.
|