• How to write unique domain authentication identifier

    How do I write udai (unique domain authentication identifier)?

    ramuyadav20 pointsBadges:
  • Security Alerts: What is tsassist.exe and browsefox.exe?

    What is tsassist.exe and browsefox.exe? My security software flags these trying to modify my registry.

    dvaughn15 pointsBadges:
  • How to secure e-commerce website?

    Hi there, I am doing my final year R&D project on how to secure e-commerce website? I am mainly looking to secure owasp top 10 threats. Would you be able to give me any advise about the steps and tools and also guidelines that I should follow to successfully overcome those issues? Kindest...

    anayatullah10 pointsBadges:
  • Would Rails 3.0 be PCI compliant?

    I apologize for the short question but would anyone happen to know if Rails 3.0 would pass a PCI compliance scan? Thanks!

    ITKE434,705 pointsBadges:
  • PCI compliance failure: Attempts some buffer overflows

    We were PCI compliant for several months straight and all of a sudden, we got this: Fail Serious Port: 21 Protocol: tcp Summary : attempts some buffer overflows CVSS Base Score : 10.0 (CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C) CVSS Temporal Score : 8.3 (CVSS2#E:F/RL:OF/RC:C) Public Exploit Available : true...

    ITKE434,705 pointsBadges:
  • What is Log Pos malware?

    What is LogPos malware like date of the malware detected, coding language, command and control channel, infecting mechanism, hiding mechanism, impact till date?

    apalkar905 pointsBadges:
  • Web application firewall for IIS

    Does anyone know what's the best web application firewall (WAF) for IIS? Also, is it useful for blocking attacks against poorly written code? I understand that WAF is required by PCI DSS so our organization needs to get one.

    ITKE434,705 pointsBadges:
  • Does temporary storage of credit card info meet PCI DSS requirements?

    For our department, we need to make sure that our temporary storage of our user's credit card information meets PCI DSS requirements. We have to make sure that deletion is compliant DoD's security standards. We thought about using MySQL but we're not sure about the reliability. What should we do?

    ITKE434,705 pointsBadges:
  • Secure credit card information for PCI compliance

    Does anyone know if there's a company / software that offers to store data (particularly credit card information securely) in exchange for a token? Also, can we view the data by using authentication and providing a token back to them? That should be enough for PCI compliance, right? Thanks!

    ITKE434,705 pointsBadges:
  • How to purge database records for PCI compliance

    I have to store some credit card information. To be compliant with PCI DSS, we need to purge the data from our disks by not just deleting the file but writing over the bytes with a random sequence of data (because that would make it harder to recover the data). We would still like to leverage a...

    ITKE434,705 pointsBadges:
  • PCI compliance: Recommended encryption key management

    This question is in reference to PCI compliance. Does anyone know of any recommended encryption key management software? Would ezNCrypt be good to use? Thanks so much.

    ITKE434,705 pointsBadges:
  • Authenticate database for PCI compliance

    We have a PCI compliant website that connects to a database but doesn't store any users' info. However, it does contain HTML / JavaScript snippets that might get rendered into the payment process. Here's my question: Do we have to authenticate the database to remain PCI compliant? Thanks!

    ITKE434,705 pointsBadges:
  • PCI compliance: Password field is present

    We currently have a huge problem with our PCI compliance. According to them, they want us to add http:// on every single page where a password field is present. Here's what my form in index.php looks like: What should we do here?

    ITKE434,705 pointsBadges:
  • Block someone else while I’m logged in

    While I'm logged in, someone else is logged in too. What should I do to block this?

    ANILRAPS5 pointsBadges:
  • Security on Client Access

    Can you please advise if there is any level on encryption on Client Access data transfer without adding SSL functionality?

    JZYoung5 pointsBadges:
  • Is this enough to be PCI compliant?

    I'm currently setting up a HAproxy to load balance between two different web servers. The majority of pages on the site require SSL. As of today, Stunnel is taking care of the HTTPS connections and passing them to the HAproxy. The HAproxy will send requests to the web servers (using HTTP). This is...

    ITKE434,705 pointsBadges:
  • Remote SMTP server is vulnerable to a buffer overflow – Failed PCI compliance

    Hello everyone, My department tried allowing the scanners IP to be accepted through IPTABLES into our SMTP port, but the scan keeps failing. Here's what we're getting: The remote SMTP server is vulnerable to a buffer overflow The server isn't crashing. We white listed the IP but we're still getting...

    ITKE434,705 pointsBadges:
  • What’s the best PCI compliant host?

    Currently, I'm using 1and1 hosting and I've been pretty impressed with the level of support so far (it's easy to use their admin panel). But now, I'm moving into e-commerce. But in order to process any credit cards, using PayPal, we need to be PCI compliant host. What would be the best option for...

    ITKE434,705 pointsBadges:
  • PCI compliance fail: SSL certificate cannot be trusted

    Our server is a CentOS box with a LAMP stack running. But we just had a PCI scan list this as a fail: SSL Certificate Cannot Be Trusted https (443/tcp) Severity: Medium Notes: none But we actually don't have a SSL certificate (we don't attempt to use it either). Should we just close port 443....

    ITKE434,705 pointsBadges:
  • Is PGP encryption available for IBM I

    Is PGP command line encryption of files available for IBM I?

    arfarn105 pointsBadges:

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

Thanks! We'll email you when relevant content is added and updated.

Following