Has anyone even vetted Verotel's script to see if there's a security hole?
What's MOST likely happening is that there's a way to insert a username and password remotely, bypassing any security features (injection, etc).
Almost every third party processor script I've ever seen has had holes (or potential holes, some I never even really looked at).
|