Prevent posting response value to asp.net page other than payment gate way

Viewed 106

I am Integrating the payment gateway 'First Atlantic Commerce' using c# asp.net(.NET framework 4.0). I have used 3dsecureAuthorize Method. On this method, the payment gateway posts the response values to our merchant website. For that created page called 'Success.aspx' which receive the some of response values from payment gateway which are posted by payment gateway after processing the transaction. I used below code for receiving the response values

request.form["responsecode"]

and updating the payment status of the transaction to the merchant website, this seems any one can post the response values to this page 'Success.aspx' from other than the payment gateway. if this happens there is a chance for updating the payment status to our website from other source without making payment through payment gateway. Can you please let me know how can we prevent the attempt of posting data to this page other than the payment gateway?

1 Answers

Response Message Signature Verification

Authorize3DSResponse Operation Responses return a verification hash Signature, with approved and declined authorization transactions, to verify that the response is from FAC’s system.

To use this Signature as verification, create a BASE-64 Encoded SHA1 hash from the following fields in this order:

  • Processing Password (a1B23c)
  • FAC ID (1234567890)
  • Acquirer ID (464748)
  • Order ID (FACTEST01)

e.g.: a1B23c1234567890464748FACTEST01

Resulting Hash Value: LOijfhLT2JO2jYaA1bXPIZNWDPg=

 using System.Security.Cryptography;

 private string ComputeHash(string Key)
 {
     SHA1CryptoServiceProvider objSHA1 = new SHA1CryptoServiceProvider();
     objSHA1.ComputeHash(System.Text.Encoding.UTF8.GetBytes(Key.ToCharArray()));
     byte[] buffer = objSHA1.Hash;
     string HashValue = System.Convert.ToBase64String(buffer);
     return HashValue;
 }

Reference : First Atlantic Commerce Payment Gateway 2 Integration Guide for Developers

Related