I am Integrating the payment gateway 'First Atlantic Commerce' using c# asp.net(.NET framework 4.0). I have used 3dsecureAuthorize Method. On this method, the payment gateway posts the response values to our merchant website. For that created page called 'Success.aspx' which receive the some of response values from payment gateway which are posted by payment gateway after processing the transaction. I used below code for receiving the response values
request.form["responsecode"]
and updating the payment status of the transaction to the merchant website, this seems any one can post the response values to this page 'Success.aspx' from other than the payment gateway. if this happens there is a chance for updating the payment status to our website from other source without making payment through payment gateway. Can you please let me know how can we prevent the attempt of posting data to this page other than the payment gateway?