|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| eCommerce Discussion Forum Ask questions about web hosting, merchant services and ecommerce issues. Topics include shopping carts, security, payment strategies, storefront partnerships, etc. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
Hi All
I have an ecommerce store with Network Solutions and something on the website shows an unsecured item when they go to the shopping cart. I checked all links and they are all secured links. Can anyone help me find the problem since Network Solutions are stumped as well? Go to http://www.gymsupply.com and place something in the cart and then you'll get a message when you check out. What is it? Help!!! Thanks for your time, AJ |
|
|||
|
Do you mean this?
"Added !Poster, Shawn Johnson Olympic Champion Poster (Qty: 1) to your cart" Some carts show messages like this due to an exploit that was fixed by adding inventory control to the cart. The exploit allowed people to change the price and quantity of the item before checking out. To stay in PCI compliance some carts had to do this. This is the ONLY message I saw so I'm thinking you mean this one. I did not know NWS had to do this but I do know some others did. Now you mention Network Solutions. I'm pulling my one site from them due to their shared hosting is NOT PCI compliant. When I signed up with them they told me it was. When I found out that it is not "through a PCI scan" I called sales and talked to 3 different sales people "called 3 times" and all 3 told me that yes shared hosting would meet my needs and yes it is PCI compliant. I called Tech support and they told me no it is not and cannot ever be due to the setup of their servers. I have been with NWS for over a year and they agreed to give me a full refund due to their sales people telling me a lie. I'm am now in the process of moving my site from them. I'm not sure if you're on a shared hosting plan with them or on their e-commerce plan so I thought I would give you a heads up. |
|
||||
|
The following dependencies are not secured on the checkout page:
http://www.gymsupply.com/custompages...r/spacer10.gif http://www.insidegymnastics.com/cont...n&sd=y&ulist=y
__________________
The best way to learn anything, is to question everything. |
|
|||
|
I want to kind of reiterate what "wige" said.
Anything found in the format of an http in an https page will result in a page stating it has unsecure items in it. There isn't any option but to fix it also. This is the list of unsecure items from the page I was on: # http://www.gymsupply.blogspot.com/ # http://www.gymsupply.com/index.asp?PageAction=CARTDETAILS&Page=1 # http://www.insidegymnastics.com/content/show/?a=426&z=1 # http://www.insidegymnastics.com/content/show/?a=430&z=1 # http://www.insidegymnastics.com/content/show/?a=431&z=1 # http://www.insidegymnastics.com/content/show/?a=432&z=1 # http://www.insidegymnastics.com/content/show/?a=433&z=1 # http://www.kipclub.com/ Good Luck, Google Junky Last edited by google junky; 11-19-2008 at 10:43 AM. |
|
|||
|
They are script/code errors. No need to worry about it. It is rare to find a page that IE wouldn't complain about. It poses no security problem.
You can fix them if you like by checking at W3C for validation. Last edited by google junky; 11-19-2008 at 02:57 PM. |
|
||||
|
The "done but with errors on the page" indicates a JavaScript error.
If you view the page source in your browser, you'll find a Javascript error on line 12, right where your Google Urchin code is. You're using the old version of Google's analytics tracking code. Here's the new code for a ecommerce site: Code:
<script type="text/javascript">
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
</script>
<script type="text/javascript">
var pageTracker = _gat._getTracker("UA-xxxxxx-x");
pageTracker._trackPageview();
</script>
old code: How can I confirm that I've entered the tracking code correctly on my pages? - Google Analytics Help Center New code: How can I confirm that I've entered the tracking code correctly on my pages? - Google Analytics Help Center
__________________
. Printer ink & toner cartridges in Canada | Web Payroll, online HR tools, time & attendance |
|
|||
|
Quote:
I just want to clarify to everyone, this isn't exactly true. Images, scripts, flash, style sheets, yes they have to be pulled through the digital certificate if on the secure page. However, links do not need to point to a secure area. Like for example, a link to a home page doesn't need to be pushed through the digital certificate. |
|
||||
|
It simply means that EVERYTHING on the page must be called using a secure server link.
Some carts will allow relative links (.../.../file.txt) but you may need to go through and change ALL links in the code to secure, and place copies of all images and dependent templates in a secure directory (depending on how your server is configured). For example, if you are calling a 'footer template' from your unsecure area of the site, it would be flagged by the server as an 'unsecure' item on the page. Usually the script running the cart has secure/unsecure access, as long as you specify in your settings you are running a secure cart and provide the secure url to the cart. - Puamana |
|
|||
|
Quote:
Visit 99% of the ecommerce websites and get into the secure environment and the links to the other pages will be unsecure, yet no errors will pop up. Why? because only items that are "included" need to be secure, like images, external script files, css files and flash files. |
|
|||
|
Quote:
My recommendation is that when you test for IE compatibility, turn on "show script errors" and make sure you don't have any.
__________________
Steve Sommers (blog) Shift4 Corporation Creators of $$$ ON THE NET(tm) Payment Processing Services |
|
||||
|
Quote:
Find your errors and fix them. Even if it is not a critical error, it is still an error and would reduce your credibility as a developer in the same way a broken image on your site reduces your credibility as a designer.
__________________
neighborhood websites for communities, associations,clubs & organizations |
|
|||
|
I am doing my internship at the company Cashtronics and they are used to dealing with security problems on websites. I am sure they can help you out.
you can find the contact on La Solution de paiement en ligne sécurisé par CASHTRONICS |
|
|||
|
make sure the links have /productabc.html instead of www.website.com/productabc.html
|
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| selling items I do not have | Tubby | Marketing Strategies Discussion Forum | 14 | 02-17-2008 04:51 AM |
| Alt Tags on Non-descript items | scot184 | Search Engine Optimization Forum | 8 | 03-06-2006 09:47 AM |
| Ethical question relating to unsecured forms... | danlefree | Internet Security Discussion Forum | 2 | 06-24-2005 04:11 PM |
| America One Funding - Unsecured Loans - $5 to $3000 per lead | mthomas | Affiliate Marketing Discussion Forum | 2 | 10-08-2004 07:07 PM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |