Any recommendations of articles or books to read about security with membership sort of sites will be real nice.
Pick up a copy of CGI Programming with Perl. It has a good chapter on security as well as lots of other information you may find helpful.
As an aside, one obvious item that's missing from your list is that you must not keep credit card numbers around longer than you need to. As soon as you've processed the transaction delete the card from your database. If it's not there then an attacker can't steal it!
-sam
In reply to Re: Paranoid about web application security
by samtregar
in thread Paranoid about web application security
by perleager
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |