<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic possible ways to make silent post url script secure in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/52053#M27351</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone know possible ways to make our script to handle authorize silent post url response secure ? if someone knows/ crack&amp;nbsp; our slient post url and try to run manullay from browser or hack script then it may create problem with our system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can we use HTTP_REFERER or something else to make this happen ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 07 Sep 2015 06:43:39 GMT</pubDate>
    <dc:creator>tatvaauthorize</dc:creator>
    <dc:date>2015-09-07T06:43:39Z</dc:date>
    <item>
      <title>possible ways to make silent post url script secure</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/52053#M27351</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyone know possible ways to make our script to handle authorize silent post url response secure ? if someone knows/ crack&amp;nbsp; our slient post url and try to run manullay from browser or hack script then it may create problem with our system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can we use HTTP_REFERER or something else to make this happen ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2015 06:43:39 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/52053#M27351</guid>
      <dc:creator>tatvaauthorize</dc:creator>
      <dc:date>2015-09-07T06:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: possible ways to make silent post url script secure</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/52066#M27363</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/14511"&gt;@tatvaauthorize﻿&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A silent post will always originate from the same IP addresses as documented here:&amp;nbsp;&lt;A href="https://community.developer.authorize.net/t5/Integration-and-Testing/Authorize-Net-Relay-Response-Silent-Post-Whitelist-IP-Addresses/m-p/48151/highlight/true#M24281" target="_blank"&gt;https://community.developer.authorize.net/t5/Integration-and-Testing/Authorize-Net-Relay-Response-Silent-Post-Whitelist-IP-Addresses/m-p/48151/highlight/true#M24281&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Richard&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2015 15:39:39 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/52066#M27363</guid>
      <dc:creator>RichardH</dc:creator>
      <dc:date>2015-09-08T15:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: possible ways to make silent post url script secure</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/53328#M28454</link>
      <description>&lt;P&gt;Another method of ensuring that a transaction Silent Post or Relay Response is legitimate and from Authorize.Net is to set an&amp;nbsp;MD5 Hash setting&amp;nbsp;in the Merchant Interface and verify the resulting hash returned in the response. This feature is documented in the AIM and SIM documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We like to verify both the hash and the IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fritz&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 15:52:43 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/possible-ways-to-make-silent-post-url-script-secure/m-p/53328#M28454</guid>
      <dc:creator>coppercup</dc:creator>
      <dc:date>2015-12-15T15:52:43Z</dc:date>
    </item>
  </channel>
</rss>

