Hello im new to these forums, seems like a busy place, im not sure of the rules in here so if i break one im sorry. I run a shell and hosting company called ukhs located at www.ukhs.com and was wondering if any of the forum users had A: visited the site and B: Registered a card payment with it - as unfortunately i have to say since i listed us a few days ago i have had 2 credit cards bounce. This may well be coicidental, then again it may not.
Credit card fraud is high among shell hosting companies, due to the fact it's a service that is well used by hackers/crackers (read it how you will), plus the fact there is never any face ot face meeting point/delivery.
Things you could do to help reduce fraud.
Verify e-mail addresses, before even attempting to process a credit card (very good idea, regardless of payment method).
Refuse to accept e-mail addresses from free e-mail providers, only those of extablished ISP's. This includes other shell providers, IE, if they use there ukshells.co.uk e-mail address, they may have a hacked account or faked details with them as well.
Never accept PO BOX numbers (except flats) for the address.
Encorage other forms of payments, by including credit card surcharges, allthough you are only permitted by law to do this to cover charges, IE, your bank charges 1%, then so do you.
Take all the credit card details. Including the CVV2 code (if available, located on the signature strip on the reverse of the card).
Never use security through obscurity. It only takes one sucessful attempt at getting a correct credit card number, and they will be back with more, or there mates will be informed.
As that photo-copies of cards are sent via fax, with some form on photo ID (no signature required, just somthing official). Some form of premium rate fax service, that will e-mail the fax's to you. This will provide you with multiple access points accross the world.
Possibly even send a postal letter to there address, that must be returned within a certain period.
These, while they may inconvienience yourself and the client. It will only do so the first time around. It also gives the aded advantage that the client knows you are tackling fraud.
Expandng on the postal letter idea: include a nice welcome letter with a special code that the user must give you (usually by e-mail). If they don't reply by a certain date, you suspend their account. This is what one small UK shell provider did a long time ago when I had an account with them. They used very good quality paper that left an impression.
The first we do after receiving an application is verify the origin of the IP address used in the signup process. You will notice after while that there is similarities between application. For example, you will find the same email address on multiple application. You might notice the application was filled up by the same ip. The login names will usually repeat themselves as well. Since the technology is at our fingertips, it is quiet easy to verify zip codes/ postal codes as well as many other information included in the application. The last thing, I usually do is a voice verification. I confirm the last four digits of the credit card as well as address and the cvv2.
I will give one idea..
just make a credit card check over the phone...
I think this will work...
This site is cool..
I`m just a kid but..
Hey can I help with the web..
I don`t want any money...
The prices are very cool..
I`m not from USA or some english country...
:}
(*I Forgot to say that I`m new to those forums 2 :}*)
I can try helping with the web page..
I can help with php ..java scripts...CSS..perl...help the users...and some other sh1tz :}
...
(*Hey what is this title of the page: http://www.ukhsshop.pwp.blueyonder.co.uk/shells.htm ?(1shapka :})*)
(*Idea: Remove the A:Hover CSStyle...it is not so cool...and change the color...*)
:P
Please contact me with your decision!
Thanks in Advance...
(*Mail me at h4cf0r@abv.bg*)