PriMoThemes — now s2Member® (official notice)

This is now a very OLD forum system. It's in READ-ONLY mode.
All community interaction now occurs at WP Sharks™. See: new forums @ WP Sharks™

Encoded Google Checkout Button

s2Member Plugin. A Membership plugin for WordPress®.

Encoded Google Checkout Button

Postby cdlambden » October 20th, 2011, 10:27 pm

Hi, I have created a Google Checkout button in pro, but there's no ability to encode the url. They could easily edit the price in the url and pay 1 cent for your product. How can I encode the url/button so they can't do that? Thanks! :)
User avatar
cdlambden
Registered User
Registered User
 
Posts: 12
Joined: August 17, 2011

Re: Encoded Google Checkout Button

Postby Eduan » October 20th, 2011, 10:37 pm

You could try to have PayPal encrypt your buttons: WP Admin -> s2Member -> PayPal Options -> Account Details -> Enable Button Encryption.

Hope this helps. :)
P.S. Remember to report back. ;)
Now officially accepting Professional s2Member installations along with Bruce C (a.k.a. Ace).

If you're interested in a Professional s2Member Installation, or a Custom Coding Job, you can send your request here.
User avatar
Eduan
Experienced User
Experienced User
 
Posts: 1154
Joined: August 27, 2011
Location: Taxco de Alarcón, Guerrero, México.

Re: Encoded Google Checkout Button

Postby cdlambden » October 21st, 2011, 7:00 am

Hi, I tried that and the url still isn't encrypted. Thanks.
User avatar
cdlambden
Registered User
Registered User
 
Posts: 12
Joined: August 17, 2011

Re: Encoded Google Checkout Button

Postby cdlambden » October 22nd, 2011, 9:35 am

Any updates on this? It's a pretty big vulnerability if they can just change the payment amout in the url and still get access. Thanks.
User avatar
cdlambden
Registered User
Registered User
 
Posts: 12
Joined: August 17, 2011

Re: Encoded Google Checkout Button

Postby cdlambden » October 23rd, 2011, 11:10 am

Would there be some way to manually encode the url? Would Google URL shortener work? Thanks!
User avatar
cdlambden
Registered User
Registered User
 
Posts: 12
Joined: August 17, 2011

Re: Encoded Google Checkout Button

Postby Jason Caldwell » October 23rd, 2011, 1:00 pm

Yes, please see this thread regarding this vulnerability:
viewtopic.php?f=4&t=15232&p=41707#p41707

Encoding your Google checkout URL produced by s2Member would make it more difficult, but it won't prevent this vulnerability entirely, because it would still be possible to tamper with the variables before being redirected to Google Checkout. So ... more difficult, yes. A long-term solution, no.

We are currently working to address this in a future release of s2Member.
viewtopic.php?f=4&t=15232&p=41707#p41707
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA


Return to s2Member Plugin

Who is online

Users browsing this forum: Google [Bot] and 0 guests

cron