• How to make a virtualization server that’s running Xen PCI compliant?

    We have a server that's running Xen with HVM and we need to make one of our VMs PCI compliant. We've already read the PCI virtualization guide and it says that we need to make sure there's no information leakage between VMs. Is there a way to make sure each OS is unable to intercept data from other...

    ITKE364,180 pointsBadges:
  • How can I be PCI compliant?

    My friend and I are developing a financial software, in turn connect it to a third party credit card company (which would be PCI compliant). As of today, we are not PCI compliant and we're not planning it. However, we want to save the four digits of PAN to help front line staff identity. So if we...

    ITKE364,180 pointsBadges:
  • Replacement for DFU

    We are looking for a product to replace DFU on our AS/400. I have found one product called DBU. In the past I had received information about Hawkeye. Does anybody have any information about this product or company? Thank you

    GreenFrog0 pointsBadges:
  • Vulnerability from PCI scan

    We recently had a PCI scan on one of our websites that was passed to us by a client. Here's one of the vulnerabilities that we got back: Network service: 80/443 Application URL: The response contains SQL Server errors. This suggests that the hazardous characters inserted by the test penetrated the...

    ITKE364,180 pointsBadges:
  • What’s the best service storing PCI sensitive data?

    I'm looking to build a web application that's going to handle sensitive PCI data (including banking numbers). What's the best service that can handle all of this data? My friend told me about Rackspace but I'm not sure about its PCI solution. I just need to make sure the database is secured and I...

    ITKE364,180 pointsBadges:
  • Can we make Google App Engine PCI compliant?

    We're working with Google App Engine but several people in our organization have said that in order to have a PCI compliant cloud solution, we need to have a private cloud environment and we can't use App Engine. Does anyone know if this is true? Can we still use Google App Engine?

    ITKE364,180 pointsBadges:
  • SSL cipher for PCI compliance on AWS

    For the past few weeks, we've been trying for PCI compliance on a load balanced EC2 instance on AWS. Here's our issue: The load balancer accepts weak ciphers. But ELB doesn't support the cipher suite so we have to manually do it one-by-one. What should we do here? What's a good strong cipher for us?

    ITKE364,180 pointsBadges:
  • Can we host a PCI compliant application on Azure?

    I've been trying to host an application on Windows Azure that would store people's credit card information of users who would want to buy monthly subscriptions for a monthly fee. We just have to store the card data as secure as possible. And we know we have to be PCI compliant. Will Azure allow us...

    ITKE364,180 pointsBadges:
  • Configure PCI compliant environment

    I have a few questions related to PCI compliance (since my organization is starting to get into credit card processing). Basically, how can we configure a PCI compliant environment? And how do we secure a build server? Thanks!

    ITKE364,180 pointsBadges:
  • PCI DSS check failing with IIS 7.0

    One of our clients is currently having their website validated so they can accept credit card payments on their site. One of the biggest failures they got back was that they're leaking the internal IP address. But they are running IIS 7.0, which we thought wouldn't do that. We checked the headers...

    ITKE364,180 pointsBadges:
  • Internet Explorer vs. Firefox

    Hello, I'm the Assistant Editor on SearchWindowsSecurity.com. I'm looking to start a discussion about what browser people are using and why. Also, is anyone considering switching from IE to Firefox, or are your plans to stay with IE? Here's some food for thought... As of Feb. 2005, an estimated 35...

    LMullen0 pointsBadges:
  • What can we fix from our PCI scan?

    I'm pretty new to PCI and my organization just got the Trustkeeper PCI Scan and we got several results including: DB Accesibility SSLv2 Supported Ton of OpenSSL related vulnerabilities Apache Tomcat vulnerabilities BIND related vulnerabilities What vulnerabilities should be fixed by my company?...

    ITKE364,180 pointsBadges:
  • PCI compliance issue with SQL injection

    We're working on a client's PCI compliance. Here's one of the failing issues: 3.1.4. Blind SQL Injection (httpgenericscriptblindsqlinjection) We found out that the issue might be with the OWA. Does anyone know how to fix this issue?

    ITKE364,180 pointsBadges:
  • How to get my Ubuntu system PCI DSS compliant

    I'm trying to get PCI compliant and a scanning company flagged our Ubuntu system for not being compliant. What should we do here? It has to do with our open_basedir, which they don't support. Thank you for your help.

    ITKE364,180 pointsBadges:
  • Failed PCI compliance check on IIS

    Our website just failed a PCI Compliance check. Our report said the site supported weak ciphers. But we thought we disabled that by turning off the SSL on our web servers. What else we need to check? Should we look at the load balancer? Thank you very much!

    ITKE364,180 pointsBadges:
  • Is there a way to isolate PCI compliance?

    Our company is currently in the process (but not storing) of credit card data. We also authorize the cards through a developed app using the authorize.net API. Now, if it's possible, we would like to limit the requirements of PCI that would affect our servers to an isolated separate environment. Is...

    ITKE364,180 pointsBadges:
  • What’s the cost of PCI compliance for a PHP script?

    I'm developing a single PHP script (it's for a new piece of software) which will collect cardholder information and store it in a MySQL database. Obviously, we're taking our security very seriously but we need some help. What scans do we need to find? After, what's the cost of PCI compliance for...

    ITKE364,180 pointsBadges:
  • PCI compliance rules for storing credit card numbers

    I apologize for the 'newbie' question but does anyone know what the PCI rules to follow are for storing credit card numbers in a database? Can anyone point me in the right direction?

    ITKE364,180 pointsBadges:
  • Storing billing data in a MySQL database: A PCI compliance violation?

    For the past several months, I've been developing a shopping cart and I need to store Name, Billing, Address and Zip Code into a MySQL database. I'm doing this because a returning customer wouldn't have to re-enter billing information. Also, I'm not storing any credit data. Just to ask, am I in...

    ITKE364,180 pointsBadges:
  • Does anyone know if Apache Tomcat is PCI compliant?

    Would anyone happen to know if Apache Tomcat is PCI compliant? I'm worried if there's any vulnerabilities where credit card PANs are stored. Thank you!

    ITKE364,180 pointsBadges:

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following