in reply to Paranoid about web application security
Regarding payment gateways, many tend to have pre-written code packs in multiple languages which I still tend to scan through to get a rough idea on how to interact with their systems. I find it easier reading (usually well commented) code than the reams of accompanying documentation.
If you are new to e-commerce, I would advise using a gateway which hosts the CC payment forms which would at least take some of the security concerns away from you.
Regards
c
`exit` and sleep;