PDA

View Full Version : Security issue with digital download


Jan
19-Feb-2003, 08:06 AM
I have just had my first fraudulent purchase, ironically it was the first payment I have ever had that passed all of the worldpay security checks :-(.

The address was correct, but the email address was not real so they were obviously trying to get hold of the digital download location to get the product.

So my point is that if you are using digital download you might want to remove the code that displays the download location on the receipt page as this removes a level of security (ie. having a valid email address on the order).

Regards,

Pneumatus
12-Mar-2003, 01:52 PM
So how do you know that the purchase was fraudulent? Perhaps they just mis-spelled their email address.

Jan
12-Mar-2003, 02:33 PM
I wasn't sure at first and tried to trace the person whose address had been used but couldn't, I decided to leave it for a while and see if they contacted me - then another one arrived with the same format email address (ended in xxx@hotmail.com), this one I did trace and spoke to the card holder who confirmed that they had not made the purhcase, it was at this point that I decided that they were both fraudulent.

Regards,