Aug 02

Businesses using VeriSign are now covered throughout the buying process. From search to browse to purchase, customers are protected from the hazards of online shopping with the addition of new trust enhancements. The best aspect of this technology for businesses is that it’s free to use.

The new features include:

  • VeriSign Seal-in-Search
  • Daily website malware scans

These new features allow webmasters to deliver trust from the beginning of the process to the end while displaying the most trustworthy logo in the industry: VeriSign. With an ever-increasing number of malicious attacks, this technology is a huge advancement for internet security.

The VeriSign Seal-in-Search feature lets those sites that utilize VeriSign SSL stand out during search engine queries. Users will immediately see the VeriSign logo in the search next to the site in the search results, shopping sites and online listings to indicate their protection and give the consumer more trust. VeriSign is collaborating with comparison shopping sites, listings and many different consumer-based websites.

A recent study conducted by online shopping center, TheFind.com discovered that search engine results displaying the VeriSign logo saw just under a 19 percent increase in click through traffic than those without. This shows consumers recognize and trust sites that display the VeriSign logo.

In addition to the Seal-in-Search and trust logo, VeriSign has also added a much needed daily website malware scanning feature. This will further protect the consumer from malicious attacks and hijackers. On the other hand, the scan prevents website owners from being attacked. The malware scans lessen the chance of a website being blacklisted by sensitive search engines.

The process is that the malware prevention service will notify customers when VeriSign determines a website is infected. VeriSign will also prove websites to customers that are infected which will be an indication to steer clear.

VeriSign has provided the strongest SSL encryption available commercially for many years. This ensures private consumer information is completely protected. Numerous Fortune 500 companies as well as some of the top banks in the world use SSL certificates to guarantee protection.

VeriSign is already by far the industry leader in consumer security. With the addition of these much-needed, fantastic features, consumers can remain at ease knowing their information is full protected from hackers, hijackers and malicious attackers. Additionally with Seal-in-Search, customers have many more secure options to complete their shopping needs.

Jul 29

Running an online shop requires a great deal of knowledge and preparation. So much so that many people give up before achieving any real results. One of the first pit stops you’ll encounter when establishing your online business is the decision of which hosting plan would be suitable for your situation. Many people start with the cheapest web hosting plan in an effort to gauge their success before making a substantial investment in their online business. The problem with this method of progression is that it greatly hinders one’s potential for the very beginning. Instead of starting with an incompetent web hosting plan, and planning to upgrade after success is achieved, it makes more sense to start with a competent hosting plan and plan for success from the beginning. Nonetheless, if you’re determined to try your luck with a shared web hosting plan, then there are a few things you should know in regards to shared hosting and eCommerce.

SSL and Shared Hosting

An SSL certificate allows you to use SSL protection on your eCommerce site. Once you have SSL protection enabled on your site you can place a seal on your checkout page that let’s your customers know that you are utilizing SSL protocol. Many customers simply will not buy a product or service from you online without knowing that your site is protected via SSL. SSL is a file transfer protocol, and in order to use this secure file transfer protocol you absolutely need an SSL certificate. The problem with shared hosting is that you cannot have several SSL certificates with most shared hosting plans. This means you cannot have more than one secure eCommerce site on your shared hosting plan, even though the plan may advertise “unlimited domains”. In order to secure each online shop you would need a new hosting account for each site, which could become more costly than simply purchasing a dedicated or VPS hosting plan.

Shared Hosting and Dedicated IP Addresses

Another potential downfall to a shared hosting plans in regards to eCommerce is the fact that you are sharing an IP block with other webmasters. This means you have to worry about the actions of websites that you are not affiliated with, as there are some cases when entire blocks of IP addresses can be disabled for spamming and other illegitimate activity. In some cases you may even share an exact IP address with other websites. Even though your sites are not related to these sites in any way, there is a distinct possibility that your search engine ranking could be affected by the action of these sites, since you share an online identity with them. In the world of eCommerce, a lower search engine ranking equates to lower sales and less profit.

Limited Server Resources

Another aspect of shared hosting that makes it generally unsuitable for a successful eCommerce site is the overall lack of server resources. Since you will be sharing a server with other users, your site will not have access to as much bandwidth, disk space and other resources that contribute to the functionality of your site. This means your site’s visitors may have to deal with slow page loading, and you may even have to deal with site downtime.

Jan 19

Most people never go through the experience of dealing with a cyber attack, so they assume that it is not something they should worry about when setting up their online business. If you’ve been operating a personal computer, then this is probably the reason why you’ve never been targeted. Hackers tend to attack networks and computers that are of value to them, so don’t be surprised if your “longstanding immunity” to attacks suddenly diminished after your online business begins to thrive. One attack in particular that you should be aware of is the infamous inference attack. In an inference attack, also known as a SQL injection, the perpetrator inserts an SQL code into a form to gain access to crucial information that is stored in on of your website’s databases. While this may sound like something that only happens to small business owners, it actually happens to large corporations as well. In fact, in recent years this kind of attack has resulted din millions of dollar in fraud. To protect yourself from an inference attack, heed the following tips.

Encrypt All of Your Site’s Data

If your website frequently exchanges sensitive date such as credit card numbers or bank information, then you’ll want to make sure all of your website’s data is encrypted with SSL or TSL. Keeping your data encrypted ensures that in the event of a security breach, the intruder will not be able to use the encrypted information to their advantage.

Use Secure Web Applications and Forms

Although there are many useful web applications available, many of these tools represent the biggest security risks for companies.  This is because hackers use these applications to gain access to the back-end of your website. Therefore, you should be very cautious about which web applications you use in the administration of your website. Make sure all applications and forms used are designed with secure code.  You should also make sure your website’s users do not have the capability of sending SQL queries, as this is how most hackers execute inference attacks. Avoiding malicious code input from hackers is the first line of defense in preventing an inference attack. You should also avoid using dynamic queries. Dynamic queries allow hackers to send and receive SQL information over the internet in plain text, therefore these queries present a substantial security risk. Many experts recommend avoiding the use of dynamic queries altogether.

Execute Updates Regularly

Keeping your operating system and website updated is an important part in maintaining the security of your online business. Many people don’t realize that maintaining the security of their website is a full time job that needs to be tended to daily. For this reason most security companies update their software as soon as a vulnerability is recognized.  To avoid an inference attack, or any other attack, you should keep you website and operating system updated, and make sure you are ware of any new developments.

Jan 12

The search for a good web hosting company can be very confusing, especially with the ever increasing selection. Each company promises they are the best, so who do you believe? Before you can make your decision, you should know that all features are irrelevant unless the web hosting service offers top notch security. Before deciding on a web host you’ll want to make sure they are capable of keeping your website secure. The following terms will help you make your decision by letting you know what you should be looking for.

Secure Sockets Layer (SSL)

SSL is an encryption protocol that keeps all of your website’s communications, both incoming and outgoing, secure from intruders. The incoming information ( credit card numbers, addresses, emails) is the most sensitive information and can be used by hackers to commit fraud with your customers’ information. For this reason SSL is one of the most important security features, and most online shoppers will not buy products or services form you if you do not have an SSL certificate posted on your website.

File Transfer Protocol (FTP)

FTP is a network security protocol that facilitates file transfer on both internal and external networks.  FTP is an important security feature because it gives the webmaster the ability to manage site accessibility and send files securely.

Secure File Transfer Protocol (SFTP)

SFTP is a stronger version of FTP, offering more of a guarantee than standard FTP by using a secure shell to transfer data over the internet and between networked computers. Serious business owners will want to make sure their web host offers this as part of their security package.

Firewall

Nearly every web host is protected by a firewall of some sort, however not all web hosts give the end-user access to the administrative functions of the firewall. If you are serious about the security of your website, then you will choose a host that grants customer access to the configuration of their site’s firewall.

Spam Filter

You may think spam is just a nuisance, however there are many hackers that use spam to plant nasty viruses on your computer. Among the bad things that can happen because of simple spam is phishing (password stealing), and even data loss caused by malicious software. Spam not only threatens the security of your website and the safety of your computer, it also consumes plenty of bandwidth and it clutters your inbox with unwanted messages. A spam filter will solve nearly all of the potential problems that are caused by spam.

Distributed Denial-of-Service (DDoS) Protection

A DDoS attack is very well know yet common attack executed by a hacker with access to multiple compromised computers. This attack is particularly dangerous because it can comprise an entire network of computers in short period of time.  Every website on the server, including yours will be affected detrimentally. In fact it is more than likely that the end-users will be affected the most by this type of attack. It is vital that you make sure your web hosting service has protection measures in place to prevent this kind of attack.

Oct 21

A quick Google search online for e-commerce solutions will garner a huge number of software solutions available for free or commercial use.  Among the free solutions available, and slowly losing its initial popularity, is osCommerce.  osCommerce is an extensive and quite possibly one of the most thorough out-of-the-box pieces of software you can find.  However, as all-encompassing as it may be, it is in severe need of a major overhaul to place it at the same level as its peers.

How it all began

osCommerce got its start in March of 2000.  Created by Harald Ponce de Leon and originally called “The Exchange Project”, osCommerce quickly began to grow in both initial popularity and capabilities.  The software is created with PHP and uses MySQL for its database core.  It can be installed on any server that utilizes these two pieces of programming.  For the past nine years, the program has been in the development stage.  Officially, as of March 2009, osCommerce released its production ready alpha product.  This release, Merchant V 3.0, includes a template system, an object-oriented backend and the ability to define the administration user name and password upon installation.  To date, the osCommerce site claims over 12,000 online stores currently using their product.

The current problems

While it is a very good and all-encompassing shopping cart program, osCommerce is not without its issues.  Installation of the program by a novice may prove to be a daunting task as a basic knowledge of MySQL as well as other web server technologies should be at the ready.  The default SSL option is initially and automatically set to “no” which is practically an open door to nefarious entities trying to gather secure information on customers.  Adding new shopping cart products is no simple task either – there are several options and features that need to be dealt with before adding in a new product, quite possibly the quickest way to creating a lot of confusion.  When you do have the program installed and your cart up and running with all of its products, adding any additional modules or templating takes quite a bit of work and may end up breaking the core of the program.  Not to mention the creators of the software do explicitly state that additions to the core are not always endorsed.

One of the best ways to avoid a lot of this hassle is to either have a seasoned osCommerce professional install the program for you or, if your web host has this option, have it installed by your hosting company.

Conclusion

If you are in need of a shopping cart program that is capable of being search engine optimized, fully featured and very robust, osCommerce is a good choice.  However, it still needs quite a bit of work in as far as installation and add-on capabilities before it can be considered a simple ecommerce program of choice.  OsCommerce is ideal for the knowledgeable and seasoned web developer, not for the novice nor the faint of heart.