Pharkie Posted February 3, 2004 Share Posted February 3, 2004 Or you could enable MD5 to improve things a bit Worldpay problems This page explains the problems with Select Junior better than I can. I can confirm though, that the issues it outlines are still present and affect anyone using Worldpay, including via the OSC contribution. That page doesn't include my technique of using a Javscript debugger, which is more likely to work than the way it suggests. So yeah MD5 would sort the main part of the insecure-ness out. The contribution needs to be changed for that to work, I think, but that would be simple. IMHO a 12-character password is secure enough, and as for its point about the callback - I've not looked into that but what it's saying makes sense. One way or the other, there are some pretty big problems with the current OSC worldpay system. If you check your orders by hand and ensure the amounts/totals make sense, then you'll be OK. Quote Link to comment Share on other sites More sharing options...
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.