Re: [WebDNA] OT: Issue with some clouds
This WebDNA talk-list message is from 2009
It keeps the original formatting.
numero = 103292
interpreted = N
texte = > I'm still a little fuzzy on the PCI compliance thing... (I haven't > done a CC site since the new regulations went into effect). If a > small merchant has a storefront site, goes through a gateway (e.g. > Authorize.net), does not store any card info, but only passes it > through the site to the gateway, and receives confirmation back, > does that merchant have to do anything more than have an SSL?I recently had to make my servers PCI compliant. It is more than simply data retention policies and SSL certificates. We used TrustWave to gain compliance. I was actually surprised at what all they checked for. They would do a scan against my servers that would take about two hours to complete. When they finished, I received a report that listed all the vulnerabilities that caused me to fail compliance. These included things such as the version of apache, FTP server, and PHP I had running on the server. I also had to remove SSLv2 support from my server, update SSH, among other things.I even had an issue come up with that way I have coded some WebDNA; in particular, my use of 'cart=[cart]'. The test that they ran against the sites in question included substituting the value of [cart] with some values that included angled brackets and other such characters, then checking to see if that string appeared anywhere on the resulting page. I solved the problem by changing to 'cart=[url][cart][/url]'. It would not have affected WebDNA, but I guess it could have affected lesser languages. I guess it could also be used to create a bogus link to a page on a WebDNA site that substituted [cart] for some javascript, which could be theoretically used for malicious purposes for anyone who followed the link.Anyway, that's what I learned from having to get PCI compliant.Dennis
Associated Messages, from the most recent to the oldest:
> I'm still a little fuzzy on the PCI compliance thing... (I haven't > done a CC site since the new regulations went into effect). If a > small merchant has a storefront site, goes through a gateway (e.g. > Authorize.net), does not store any card info, but only passes it > through the site to the gateway, and receives confirmation back, > does that merchant have to do anything more than have an SSL?I recently had to make my servers PCI compliant. It is more than simply data retention policies and SSL certificates. We used TrustWave to gain compliance. I was actually surprised at what all they checked for. They would do a scan against my servers that would take about two hours to complete. When they finished, I received a report that listed all the vulnerabilities that caused me to fail compliance. These included things such as the version of apache, FTP server, and PHP I had running on the server. I also had to remove SSLv2 support from my server, update SSH, among other things.I even had an issue come up with that way I have coded some WebDNA; in particular, my use of 'cart=
[cart]'. The test that they ran against the sites in question included substituting the value of
[cart] with some values that included angled brackets and other such characters, then checking to see if that string appeared anywhere on the resulting page. I solved the problem by changing to 'cart=
[url][cart][/url]'. It would not have affected WebDNA, but I guess it could have affected lesser languages. I guess it could also be used to create a bogus link to a page on a WebDNA site that substituted
[cart] for some javascript, which could be theoretically used for malicious purposes for anyone who followed the link.Anyway, that's what I learned from having to get PCI compliant.Dennis
"Dennis J. Bonsall, Jr."
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Showif, Hideif reverse logic ? (1997)
WebCat2 - Getting to the browser's username/password data (1997)
[showif]/[hideif] question (1997)
Convert words (2002)
Is this possible, WebCat2.0 and checkboxes (1997)
WC 2.0 frames feature (1997)
WebMerchant Orders Won't Process (2002)
OSX Applescripts -- Anyone? please? (2004)
lookup (1998)
Searching multiple records for certain info (2000)
sorting by date (1999)
WebCat hosting providers? (1997)
WCS Newbie question (1997)
Simple way to create unique SKU (1997)
WebCatalog [FoundItems] Problem - AGAIN - (1997)
CVS Files for databases (2000)
Re:Off Topic: Frames Killer? (1998)
WebDNA for Dummies (2003)
WC2b15 - [HTMLx]...[/HTMLx] problems (1997)
Pithy questions on webcommerce & siteedit (1997)