Guest Post: Jeff Finkelstein of Customer Paradigm: Don’t lock your door and leave the window open

A guest post on security from Customer Paradigm

At eBoundHost, we work with a variety of developers, designers, and security consultants to help our customers make the most of their web presences beyond the server environment.  Jeff Finkelstein of Customer Paradigm is a top Magento and WordPress developer that has helped countless clients secure their sites.  He has some pointed about the importance of patching your e commerce software.


If you run a Magento site, you probably take credit cards for payment.  It’s no secret that hackers want to steal your customers’ credit card  information, so that they make fraudulent purchases or sell the credit card numbers online.

Most eCommerce platforms  like Magento don’t actually store and save credit card information. When the user is in the cart, entering their credit card information, the credit card data is not stored on the server.  Rather, it’s encrypted and securely sent to the credit card company.

If the credit card number, expiration date, security code, name on the card, billing address on file and a few other data points are accepted (i.e. the person is not over their spending limit for the amount you’re trying to charge), then the credit card company will send back an authorization code, letting you know the credit card was accepted for the purchase amount.

That’s how it’s supposed to work. But, if someone was able to get into the code of your site, then  they can inject a little bit of code that watches and records the credit card information, then sends it off to a nefarious person.

Usually the attack is not against the core code of the eCommerce site, but a security loophole somewhere else.

Sometimes attackers are able to gain entry to a site because there is a security vulnerability that should have been patched, but hasn’t;  an insecure plugin, an out-of-date extension, or a misconfigured setting that isn’t even connected to your eCommerce site.  The main components of your eCommerce site might be very secure.  But if another portion of your site is not, it’s like leaving the side window of your house wide open and leaving on vacation.  Sure, the front door is locked, but there’s another, very easy way into the house.

If your eCommerce software developer (Magento, WooCommerce, etc.) releases a patch, it’s extremely important to install it.  Because when a security patch is sent out, the first thing hackers do is reverse engineer it to see how a site could be vulnerable if that patch isn’t applied.

If you patch your site, you’ll be in better shape.  If you don’t, the security patch is now an evildoer’s how-to guide for attacking your site.  This means failing to patch your site in a timely fashion is doubly dangerous.  Once the patch is released, unpatched sites are at even higher risk of being compromised.

We recommend using a version control system such as  git or subversion on your server, so that you can easily see if any key files have been changed.  You can also use it to run an automated scan for new, changed or removed files – key warning signs that someone has been tampering with your site.  

For example, on a Magento site, I know that if the CC.php file in the core code has been changed, the site is likely to have been attacked – this is one of many points to check for possible problems.

Bottom line: keep up to date with patches, and use a version control system to let you know if anything new has been added to the site.

I hope this helps!  My team is here to secure your site ahead of the upcoming holiday – you can call me at 303.473.4400 or visit http://www.CustomerParadigm.com/Magento for more information.




Read This Next:




eBoundHost is the best. I have dealt with many hosting providers over the last 10 years. eBoundHost surpasses them all. Absolutely the highest level of quality service anywhere. Do yourself a big favor and sign on with eBoundHost.

Dave "Infodave" Beightol

Awesome Service And Excellent Customer Service!

Cory Farbman

Excellent response to questions and issues. Fabulous uptimes. Personable tech support.

Lisa Cowan

GREAT customer service and tech support, with professional, yet personable service.

J. Bitner

Every time I call with a problem or question, Everyone, especially Denis has always stepped up to the occasion. As usual he solved yet another problem I had. You have a superlative customer service. It doesn't get any better. Keep it up guys.

Jason M

1) Their technical support people are always available to help with questions. 2)Server and network speed excellent. 3)Everything works great. 4)I highly recommend them!!!Thank you.

Jindrich Radic

I have worked with many hosting companies over the course of my years in the website building and design business. I can say with certainty that eBoundHost.com is among the elite companies. I would and have recommended them to anyone.

Jim Nickerson

No better web host on the market! Support is second to none.

Roger Hamilton

Over the years, I've dealt with many companies. None come close to equaling the service and price offered by eBoundHost.

Jerry Stark

I'm Stan Bogdashin, a customer of your hosting company for the past 2 years. Our company provides web design, development and Search Engine Optimization (SEO) services. Want to thank you for helping us by providing great hosting seamless support - this is why I continue to recommend you and don't use anyone else for hosting!

Stan Bogdashin

eBoundHost.com has the best customer service in ANY industry. Their support staff answers phone calls and emails immediately and they have time and time again gone over and above their responsibilities to make sure I am taken care of and that my clients are happy. I have many websites hosted here from small business to corporate level and have dealt with many hosting companies in the industry and eBoundHost.com is by far the BEST hosting provider there is. Great prices, great service, great hosting packages, and a killer reseller program! THANK YOU AGAIN :)

Shannon

EXCELLENT across the board, super quick reply to questions (about 15-30min). Outstanding! Loads of features, excellent price! Loads of space and bandwidth!

Beau B.

eBoundHost provides the very best service I've experienced in hosting. It takes less than 24h to get an answer to any question. They're great.

Fabien Papleux

eBoundHost.com has been a dream to work with. My questions are answered in minutes, the price is very reasonable, the interface is great, I am very happy with how smooth everything works.

Paul

I was just looking over our emails and adding up how much time you guys have taken to get me squared away with my new eboundhost account. I can't tell you what a relief it is to have fast, dependable hosting and the kind of immediate support I've gotten from you, after having struggled with a sub-standard host for years. eboundhost has, in the short time I've been with you, already saved me hundreds of dollars of billable time. My thanks.

Bart W

Reliability and customer service that is rare and refreshing. We have been using eBoundHost for several years and unlike many companies who's service wanes over the years, the staff at eBound has consistently delivered top notch performance. Bravo!

Don Bailey

We at Alico have 4 domain names which we started subscribing at eBoundHost since more than 4 years. In brief they are the best webhosting provider with a sexy Control Panel and perfect fast response support.

Ahmed Hussein
AlicoUAE

SUPER SUPPORT - even during "off hours" - Sundays & holidays. Responses have always been within minutes of the initial call or email. The BEST vendor I have ever used in my 10 plus years as a webhosting services consumer.

EG Pursley

There is not a place on this Planet that you can get better service, support or hosting!

Pat

I came to eBoundHost after a very bad experience with a so called "big boy" - you know one of those places you are only a number. I have been a satisfied customer for more than 4 years now. The support is second to none.

Gary Hutchison

Find the right cloud VPS Size for your website

Smaller websites with less traffic

Multiple websites or large traffic-intensive websites

 

1
CPUs
1.5
GB RAM
50
GB Storage
2
TB Transfer

$25/month

Get Started

30 day money back

 

2
CPUs
3
GB RAM
100
GB Storage
3
TB Transfer

$40/month

Get Started

30 day money back

 

4
CPUs
5
GB RAM
200
GB Storage
5
TB Transfer

$50/month

Get Started

30 day money back

 

6
CPUs
7
GB RAM
450
GB Storage
7
TB Transfer

$65/month

Get Started

30 day money back

 

8
CPUs
9
GB RAM
600
GB Storage
10
TB Transfer

$99/month

Get Started

30 day money back

 

10
CPUs
10
GB RAM
1000
GB Storage
12
TB Transfer

$125/month

Get Started

30 day money back