November 26th, 2008 at 8:49 am    
Hello Website Forge community. I'm sure you are all preparing for your Thanksgiving feast. Here is a quick update on features added to Website Forge the following couple weeks.
1) We have added new tax application rules. One can now control whether each particular tax is based on billing or shipping address, apply tax to products shipped FROM particular source and with particular value in a field (possible to have different "Tax Exempt"-like fields for different taxes). This will help those who have troubles with new California tax configurations.
2) For sites selling photos, the parent product can now be excluded from shipping (a collage or other processing work) while child products (prints) can be shippable.
3) Recently Viewed Items. You can set up an item list with "Affected By" = "Recently Viewed items". So you can show a list of recently viewed products anywhere.
4) Improvements allowing to export large numbers of orders at once. For high volume sites exporting orders for UPS or other label printing systems.
5) When using virtual wallet / gift certificates, they are enabled by default on the checkout screen and a gift box icon is shown near the note (for those people who may not see the text.
6) Color palette selector for label/value formatting in layout builder. Also can set the Control Line to display buttons one under another (not in one line).
Thanks for all your support and have a Happy Thanksgiving.
Shane Merem
Website Forge
Web Design and E-commerce web sites
The goal of this posts is to help you realize and achieve the most success from your website
|
November 20th, 2008 at 8:09 am    
Hello Website Forge community.
I received the following email from UPS:
-------
UPS OnLine® Tools Upgrade Notification
You are receiving this communication to notify you of changes that could affect your UPS OnLine Tools beginning March 1, 2009. Action may be required to ensure that the change does not adversely impact your business and use of the tools.
On March 1, 2009, UPS is moving from unchained to chained Digital Certificates to improve security when using the Internet. The change requires your system to support the Secured Socket Layer (SSL) Version 3.0 to be compatible with the new Digital Certificates.
It is highly recommended that you validate your configuration and upgrade your digital certificate to avoid connection breaks to your UPS OnLine Tools application. ........
-----------
After talking to our development team I was told that this should not affect Website Forge in any way.
This email is for the customers that generally email us to ask this very question.
Thanks and have a great holiday sales season!
Shane Merem
Website Forge
www.websiteforge.com
web site design and ecommerce
The goal of this posts is to help you realize and achieve the most success from your website
|
November 6th, 2008 at 3:42 pm    
As some of you may already be aware, Websiteforge has been audited lately for PCI compliance. The following is a list of issues and the results of our findings. Please review this when you receive test results about your site. As always, feel free to submit your test results to support@websiteforge.com so we can review them for you and advise.
REVIEW:
OpenSSH Duplicate Block Denial
of Service Vulnerability
A version of OpenSSH prior to 4.4 is running on this host. This version
is affected by a Denial of Service vulnerability. However, an attack can
only be performed if version 1 of the SSH protocol is enabled.
Note: Vulnerabilities which result only in denial of service do not affect
PCI compliance; however, they may still be critical to your systems.
Service: SSH-2.0-OpenSSH_3.9p1
CVE: CVE-2006-4924
NVD: CVE-2006-4924
Bugtraq: 20216
CERT: 787448
CVSSv2: AV:N/AC:L/Au:N/C:N/I:N/A:C (Base Score:7.80)
FALSE ALERT. We do not have and never had SSHv1 enabled.
ProFTPD Command Truncation
Cross-Site Request Forgery
Vulnerability
The version of ProFTPD running on the remote host splits an overly
long FTP command into a series of shorter ones and executes each in
turn. If an attacker can trick a ProFTPD administrator into accessing a
specially-formatted HTML link, he may be able to cause arbitrary FTP
commands to be executed in the context of the affected application
with the administrator's privileges.
Service: 220 WebsiteForge FTP Server (www.websiteforge.com) ready
CVE: CVE-2008-4242
NVD: CVE-2008-4242
Bugtraq: 31289
Reference: http://bugs.proftpd.org/show_bug.cgi?id=3115
CVSSv2: AV:N/AC:H/Au:N/C:P/I:P/A:P (Base Score:5.10)
Valid alert. Software upgraded and patched, issue resolved.
OpenSSH X11 Session Hijacking
Vulnerability
OpenSSH is prone to a vulnerability that allows local attackers
to hijack forwarded X connections. The system must have both
IPv4 and IPv6 enabled at the same time for this to be exploited.
Successfully exploiting this issue may allow an attacker run arbitrary
shell commands with the privileges of the user running the affected
application. This issue is known to affect OpenSSH 4.3p2, though
other versions may also be affected. This vulnerability will trigger on
any SSH banner version prior to 'openssh-5'. OpenSSH packages
shipped with Red Hat Enterprise Linux 4 and 5 are not vulnerable to
this issue. However, Red Hat Enterprise Linux 2.1 and 3 are affected.
Service: SSH-2.0-OpenSSH_3.9p1
CVE: CVE-2008-1483
NVD: CVE-2008-1483
Bugtraq: 28444
CVSSv2: AV:L/AC:H/Au:S/C:C/I:C/A:C (Base Score:6.00)
FALSE ALERT. Our systems have IPv6 disabled and therefore are not affected.
Multiple Vulnerabilities in lighttpd
Prior to 1.4.20
The version of lighttpd running on this host is prone to multiple
vulnerabilities. These include a failure to properly sanitize user input
which could lead to information disclosure, a memory leak when
processing multiple headers that could lead to denial of service
conditions, and the ability to circumvent URL rewrite and redirect
patterns using encoding. Refer to the included references for more
information.
Service: lighttpd/1.4.18
CVE: CVE-2008-1531, CVE-2008-4298, CVE-2008-4359,
CVE-2008-4360
NVD: CVE-2008-1531, CVE-2008-4298, CVE-2008-4359,
CVE-2008-4360
Bugtraq: 28489, 31434, 31599, 31600
Reference: http://trac.lighttpd.net/trac/ticket/285Reference: http://
trac.lighttpd.net/trac/ticket/1720Reference: http://trac.lighttpd.net/trac/
ticket/1589Reference: http://trac.lighttpd.net/trac/ticket/1774
CVSSv2: AV:N/AC:L/Au:N/C:N/I:N/A:P (Base Score:5.00)
Valid alert. Removed the software because it was installed for a customer who has left and never used it.
The goal of this posts is to help you realize and achieve the most success from your website
|
October 20th, 2008 at 1:18 pm    
Here are the latest updates to the Website Forge core system:
- Froogle (google base) attributes are automatically mapped to fields on the Froogle Export form to reduce customer errors.
- Image Lists can show out-of-stock overlays.
- Default distance for zip distance search can be specified.
- Tree options performance optimizations - thousands of items should not be a problem to display in a tree.
- DHL realtime rating option.
- Zero-downtime publishing - the old version of the site will be 100% accessible during the publishing process, until the moment new published version is ready.
- Stricter validation of discount coupons.
- Detection of different error conditions in file uploader.
- File uploaders validates file types (won't allow to upload WMV when FLV is expected, etc).
Thanks, Shane Merem
www.websiteforge.com
Web Design and E-commerce
The goal of this posts is to help you realize and achieve the most success from your website
|
October 7th, 2008 at 9:51 am    
Hello everyone. Here are a few upgrades added last Sunday:
1) Custom Date / Custom Number options for products now available
2) Custom Weight option added
3) URL fields in the layout builder can be set up to open in same window/new window/popup.
4) Instant unsubscribe links for blog and membership.
5) Ability to quickly unsubscribe a member from blog categories (all or some) on Edit Member form.
6) Image / Image List fields and option images display a hand cursor if they are clickable to help people see they can click the image.
REMINDER! Make sure your site is indexed properly by Google and Yahoo!
Don't forget how valuable it is to configure your web site for Google Sitemaps! It is a built in feature of Website Forge to provide important page and product informationto Google! Contact support so that we can help you with this feature.
Shane Merem
www.websiteforge.com
Web Site Design and E-commerce
The goal of this posts is to help you realize and achieve the most success from your website
|
September 5th, 2008 at 1:53 pm    
Following are upgrades performed :
1) Users can use Java uploader in their image store. When the "Upload Files" button is clicked, the link in the top right corner of the window can be used to switch to the java mode. The system remembers last used upload mode.
2) Place Ad module supports using File Store for uploading files to fields of type File. On Frame Settings page of an Edit Item frame a file field can be set up to display a File Store selector instead of regular "Click here to upload" link. Previously this was only available for Image fields, now it can be changed for File fields too.
3) Member's File Upload notification can be turned on in Membership general settings.
4) Java uploader can be enabled for member ads on Ad module General Settings form. For it to work, image/file fields on the Edit Item page must be changed to Image/File Store (like in item 2).
5) On the Frame Settings page of a Search Box you can set some fields as "required". The search box will show a message and won't do any search until all required fields are specified.
6) In the Frame Settings of a Search Box you can set it to redirect to a details page when only one result is found.
7) "Required" setting is now supported for Product Options of types "Custom Price", "Custom File" and "Custom Text".
8) Zip Code search now displays nearest members first. Performance optimizations were applied to it.
9) Product Popularity now supports sorting by SKU and CSV export.
The goal of this posts is to help you realize and achieve the most success from your website
|
July 1st, 2008 at 10:50 am    
Would you like to be able to avoid fraudulent charges and help warn others?
With the help and suggestions from Chuck at www.clrmarine.com (and others) we decided to put up a BLOG of fraudulent activity to help warn other Website Forge merchants of possible fraudulent activity.
We will also start posting some tips and advice to help identify and avoid fraudulent transactions.
Go to www.support.websiteforge.com and clock the FRAUDNET button on the menu.
I have protected the page with the following username and password:
user: fraud
pass: net
Please email any possible fraudulent activity to support@websiteforge.com and I'll post it to the blog so we can warn others.
Shane
The goal of this posts is to help you realize and achieve the most success from your website
|
June 18th, 2008 at 10:52 am    
I'm writing this message because I feel it's very important that our community of online e-commerce retailers understand how fraud impacts your business.
Kevin from www.diveprodivegear.com has a horrific story that started with $28,000 of fraudulent orders. The end result was a frozen credit card account and over $7,000 of HIS LEGITIMATE money held by Visa and Mastercard.
Keep in mind that Kevin identified and refunded this money thinking he was doing the "right thing".
** IMPORTANT NOTE **
Kevin mentions Linkpoint many times in this story. Keep in mind that Linkpoint is merely a gateway and does not make these decisions. The decisions are made by the actual processing bank -- in this case "First Data Corp.". Which, in turn is regulated by Visa/Mastercard, etc. So "Linkpoint" is only the gateway that happens to be the company handling the complaint.
I'll post Kevin's messages verbatim since he does a good job of telling his story...
| From: |
kob159014 |
| To: |
smerem |
| Posted: |
16 Jun 2008 06:36 pm |
|
Subject:
|
Credit card fraud
|
|
|
Shane -- thanks very much for your prompt return of my call on Friday. I really appreciate it. Here's what happened ...
Over the last couple of months, we had 4 fraudulent orders get through the automatic Linkpoint authorization process and show up as new orders. These were large ($5000 - $11,000) orders and were suspect to us, so we called the credit card company, confirmed the credit card was stolen, cancelled the orders and processed credits to the cardholders. So far, so good.
Then our Amex orders started getting declined and shortly thereafter all our orders. Without notification, Amex's computer had decided that we were high risk and had suspended our account. That triggered Linkpoint into doing the same (again without notification). All this after 1) Amex approved the fraudulent transactions before we ever saw the orders and 2) in spite of the fact that we notified Amex of the fraud and promptly processed credits to the cardholders. Since last Friday, we have had to process orders manually and hold transactions while I sort things out with Amex and Linkpoint.
Amex has reinstated our account, and Linkpoint says they will within the next few days, but they aren't terribly responsive.
In any event, have you had website clients experience this before and, of so, what were they able to do to prevent re-occurance ?? For example, do they automatically decline any orders where the Bill To and Ship To don't match, then process those manually ??
Any advice is welcome. Thanks for listening -- KOB.
_________________
KOB www.DiveProDiveGear.com
Toll free: 1-877-55-DIVER
|
I asked Kevin to post the details so I could share......
| From: |
kob159014 |
| To: |
smerem |
| Posted: |
17 Jun 2008 12:16 pm |
|
Subject:
|
Re: Credit card fraud - the details
|
|
|
Hi Shane,
Here are the details ...
If you look on our website details, you will see the following orders:
#70600482 5/10/08 $7K+ Visa
#70600434 4/23/08 $5K+ Amex
#70600380 3/27/08 $10K+ Amex
#70600303 2/13/08 $6K+ Mastercard
Each of these orders was processed via Linkpoint and authorized prior to them being forward to us. Because of the large $ value, odd nature of the purchases (e.g. 20 of the same dive computer) and foreign Ship To address, we suspected that they were fraudulent and contacted the credit card company. When we confirmed that the credit cards were stolen, we cancelled the orders. Because the transactions had been approved by either the issuing bank or Amex, the funds had been automatically transferred to our bank account, so we also had to issue credits to the cardholders.
All of the above seemed to be "doing the right thing" and the credit card companies seemed to appreciate our efforts. We have not had a single bad transaction process to completion since opening in June 2007. And each of the Amex investigations was settled in our favor. There were no investigations for the Visa or MC transactions.
Nonetheless, last Tuesday 6/10, our Amex transactions started getting declined. At first, we thought that the customers were entering some incorrect information. However, just by coincidence, I had called Linkpoint and Amex and requested that they reimburse us for approx. $500+ each in credit card processing fees that they had charged us for the fraudulent transactions. Seems fair, doesn't it ?? They approve a transaction and charge us BIG fees, then we discover it's bad, refund the full amount and are out the fees. In this case, these 4 orders were more than $1000 in credit card processing fees.
So, when I spoke with Amex about these fees, they told us our account had been terminated, due to high risk. That is the ONLY notification that I have received to date. And I subsequently found out that the decision to terminate was made by a computer !! OK, I was pissed off and removed Amex from our website, but felt that was not the end of the earth because most orders are not Amex and most people have another credit card in addition to Amex.
Now it gets fun ... when Amex terminated us, they automatically put you on a TMS (terminated merchants) list, which is published to ALL credit card companies. So, Linkpoint picks that up and also terminates us (again, no notification). We realize that somethings up with Linkpoint on Thursday evening 6/12, when ALL orders start getting declined.
So, Friday most of the day I am on the phone with Linkpoint and Amex. Linkpoint says it's their policy to automatically terminate a merchant if they show up on the TMS list. They also say they'll reinstate if Amex takes us off the TMS list.
Now ... you're gonna love this ... I call Amex and finally get a nice woman who says something like "the computer did it automatically, let me take a look". I give here some details and a few minutes later she comes back and says something like "you shouldn't have been terminated, I will take you off the TMS list and can reinstate you with Amex if you'd like." Well, DUH, of course I'd like. So, she says "give me an hour or so and you will be reinstated". She also says that Linkpoint can confirm with them that they're taking us off the infamous TMS list.
So, now I am back on the phone with Linkpoint. And I tell the guy that we're now back in Amex's good graces and would he please reinstate us on Linkpoint for our Visa, Mastercard & Discover. He calls back several hours later and says that they will reinstate us, BUT just need to verify some orders. So he gives me a list of orders that are higher in value and asks me to fax copies to him, which I do. It's now about 4:30p on Friday.
Obviously, this guy's going home for the weekend, so we're unable to process any creidt cards over the weekend, which is usually a busy time for us. But, on your advice, I had put the website on manual, so at least the orders came in and we'll process the credit cards when we get reinstated at Linkpoint. We were able to log into our Amex account on Sunday evening, but can't automatically process Amex cards on our website, because they authorize through Linkpoint.
So, yesterday (Monday 6/16) I spoke with the Linkpoint guy and he says they're checking out the orders and will reinstate as soon as that's completed and they verify we're off the TMS list. Linkpoint does NOT seem to be in any big hurry to help their merchants (at least from our perspective).
That's where we are right now. Still accumulating orders that will need to be manually processed once we're reinstated with Linkpoint. I am calling this guy pretty regularly so that he knows I won't go away. I am hoping that we'll get reinstated today, but he makes no promises.
LESSONS LEARNED:
1. Pay very close attention to the orders coming in and, if you suspect fraud, confirm with the credit card company and credit the cardholder immediately. We were told by both Amex and Linkpoint that we had done the right thing by acting immediately in reporting these transactions and quickly processing the credits.
2. You will NOT be notified in a timely manner by either Amex or Linkpoint if they decide to suspend or terminate you. Orders will just start being declined.
3. You cannot prevent the bad guys from attempting fraud with stolen credit cards on your website. And some of the transactions will be approved. If they are approved, it counts against you even though you didn't do anything wrong.
4. In the near term, we are going to continue to process credit cards manually via the Linkpoint merchant portal, even after we're reinstated and could do automatic authorization, so that we will not get a fraud transaction that is automatically authorized. This has been too painful a process.
I will keep you posted on the outcome -- KOB.
_________________
KOB
www.DiveProDiveGear.com
Toll free: 1-877-55-DIVER
|
Later the same day Kevin sent me this message....
| From: |
kob159014 |
| To: |
smerem |
| Posted: |
17 Jun 2008 03:34 pm |
|
Subject:
|
Re: Credit card fraud -- update
|
|
|
Shane -- just got off the phone with Linkpoint. Reinstatement process has started (as of this morning). The party line is that it takes 24-48 hours, but the customer service person seemed to think it would take less time based on where we are in the process right now.
Hope the earlier details (sorry for the lengthy message) and this update were useful.
Thanks -- KOB.
_________________
KOB
www.DiveProDiveGear.com
Toll free: 1-877-55-DIVER
|
And the most recent update...
| From: |
kob159014 |
| To: |
smerem |
| Posted: |
17 Jun 2008 07:54 pm |
|
Subject:
|
Re: Credit card fraud -- update
|
|
|
Shane -- it gets better. About an hour ago, Linkpoint called and said that they are NOT reactivating our account, in spite of the fact that this morning they said that they were and that Amex has reactivated us, because of the fraudulent attempts (no actual losses, just attempts).
After a heated discussion (and some threats of legal action), they have agreed to reactivate our account for about 2 weeks to give me time to find another credit card processor. They are also holding more than $7000 of my money, just in case.
So, I will be contacting Dale Spenrath to find out who he can hook me up with to process our credit cards.
This is SO painful and time-consuming, you cannot imagine. Orders are coming in and we still cannot process the credit cards, so we're now at a point where we're having to ship some small orders (< $100) without having received payment. The large orders we're not shipping yet (too much risk).
Hope this saga continues to help -- KOB.
_________________
KOB
www.DiveProDiveGear.com
Toll free: 1-877-55-DIVER
|
I talked to Dale Spenrath, our Linkpoint provider. He is working with Kevin trying to see what he can do to help Kevin. Dale is not Kevin's Linkpoint agent however he is happy to pull any strings he can for all of our sake.
I'm waiting to hear from Dale to see if he was able to help. The main feeling is that the "First Data" computer is not going to change it's mind :).
In the old days everyone had some type of "banker" on the other end. Now it's just computers -- so we are at the mercy of the bits and bytes of a machine.
One important point I would add to Kevin's advice is to NEVER refund a fraudulent chargeback. Kevin had paid his 3% to charge the card and when he refunded it (thinking he was doing the "right thing") he was charged the 3% again -- Losing around $500.00 in fees that will never be refunded.
Either VOID the transaction or let the cardholder do a chargeback -- it's cheaper for the retailer.
Please post comments and questions for Dale, Kevin and myself to try to answer.
Shane Merem
www.websiteforge.com
Web design and e-commerce
The goal of this posts is to help you realize and achieve the most success from your website
|
June 5th, 2008 at 10:18 pm    
Hello everyone. Some of you encouraged me to visit the Chicago Internet Retailer Expo this year. So I have purchased my tickets!
I'll be there from June 9th to the 12th.
A few of our Website Forge partners will be there too. Justin from www.gandlclothing.com and Brian Shockley from www.shopbakersnook.com to name a couple.
If anyone else is attending.. Drop me a line and I'll see if I can meet up with you to say hello.
The web site for the show is: http://www.internetretailer.com/IRCE2008/
Shane Merem
www.websiteforge.com
Web site design and e-commerce
The goal of this posts is to help you realize and achieve the most success from your website
|
June 1st, 2008 at 5:31 pm    
Today we received a few complaints that customers using USPS (US Postal Service) could not check out.
The error the customer received was "No Shipping Options Available".
After investigation we found that the USPS shipping API (web based shipping rating service hosted by the US Post Office) was having technical problems.
As far as we see this issue has been resolved by the Post Office.
Please let us know if you see any other issues. We cannot do anything when this type of issue occurs because the error is on the side of the Post Office.
The good news is -- this is a rare event. Let's hope the USPS keeps up and running in the future.
Shane Merem
www.websiteforge.com
The goal of this posts is to help you realize and achieve the most success from your website
|