Go Back   3dCart Shopping Cart Software Forums > Shopping Cart Software > Store Design

Reply
 
Thread Tools Display Modes
  #1 ()  
Old 04-26-2008, 10:17 PM
bristweb bristweb is offline
3dCart Power User
 
Join Date: Dec 2007
Posts: 141
Default PCI compliance

during a recent PCI compliance test, I noticed a warning which could be easily fixed

Quote:
Security warning found on port/service "http (80/tcp)"

Plugin "Web Server Uses Plain Text Authentication Forms"
Category "Web Servers"
Priority Ranking "Medium Priority"

Synopsis : The remote web server might transmit credentials over clear text Description : The remote web server contains several HTML forms containing an input of type 'password' which transmit their information to a remote web server over plain text. An attacker eavesdropping the traffic might use this setup to obtain logins and passwords of valid users.

Solution : Make sure that every form transmits its results over HTTPS

Risk factor: Medium / CVSS Base Score : 5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N) Plugin output : Page : /myaccount.asp Destination page : login.asp?ordertracking=1 Input name : password
I have made the navigation on the site point to these pages, however this should be done automatically. any form which requests a password should be made secure without additional action from the user or administrator.
__________________
Who is Ron Paul?

Last edited by bristweb : 04-26-2008 at 10:20 PM.
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 12:42 AM.


Powered by vBulletin® Version 3.6.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8