Another solution I ran across: cron job to remove sensitive customer info from the exposed server and download to a secure, essentially offline server.
Obvious disadvantage: you have to do all of your order processing from the back end.
However, if your online store is only one facet of your operation, you might have to populate an offline order system anyhow.
Best regards,
Alan



Joined: 11/30/2007