- Posts: 1
- Thank you received: 0
Securepay Payment plugin database table
- Sheila Greco
- Topic Author
- Offline
- New Member
-
Less
More
7 years 1 month ago #115829
by Sheila Greco
Securepay Payment plugin database table was created by Sheila Greco
Hi Tuan,
we have purchased Membership pro, and the Securepay payment plugin.
After inputting my securepay login and password, I happened to open up my database tables. and in the
xxxx_osmembership_plugins table, under the os_securepay row, I was distressed to find the my login and password
to securepay has been stored as plain text in the params column. yikes.
Now.. Seriously????
Are we to believe that storing a plaintext password that can access payment gateway system that controls virtually unlimited amounts of money from our financial institution is a good idea?
I have been a programmer for many years, and although there is no BULLETproof way to store that info, couldn't it at least be obfuscated or encoded somehow? I could do a simple RSA encryption class and excode it byte-by-btye.. I realize there is no way to protect my access method given that PHP is a open source files kind of setup.. but I know I could sure at least make it VERY HARD for someone to figure out how I was encoding/decoding..
we have purchased Membership pro, and the Securepay payment plugin.
After inputting my securepay login and password, I happened to open up my database tables. and in the
xxxx_osmembership_plugins table, under the os_securepay row, I was distressed to find the my login and password
to securepay has been stored as plain text in the params column. yikes.
Now.. Seriously????
Are we to believe that storing a plaintext password that can access payment gateway system that controls virtually unlimited amounts of money from our financial institution is a good idea?
I have been a programmer for many years, and although there is no BULLETproof way to store that info, couldn't it at least be obfuscated or encoded somehow? I could do a simple RSA encryption class and excode it byte-by-btye.. I realize there is no way to protect my access method given that PHP is a open source files kind of setup.. but I know I could sure at least make it VERY HARD for someone to figure out how I was encoding/decoding..
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
7 years 1 month ago #115853
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Securepay Payment plugin database table
Hi Sheila
At the moment, yes, that information is stored as plain text in database and I agree that it's not safe in case someone hack the site and got the database
I will try to find a way encrypt/decrypt that data sometime next week (I am sick at the moment and will need about one week to get recovered)
Hope that's OK for you
Regards,
Tuan
At the moment, yes, that information is stored as plain text in database and I agree that it's not safe in case someone hack the site and got the database
I will try to find a way encrypt/decrypt that data sometime next week (I am sick at the moment and will need about one week to get recovered)
Hope that's OK for you
Regards,
Tuan
Please Log in or Create an account to join the conversation.
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.