Announcement

Collapse
No announcement yet.

Hiding Scripts Page – PCI Compliance Failed!

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Hiding Scripts Page – PCI Compliance Failed!

    Hi Guys,

    Just a quick message, my website is failing the PCI compliance test as the scripts page is viewable, any way i can hide this please?

    The hosting company have said there is nothing they can do and ive just spoken to one of the support guys over the phone and he said they cant do anything either, so im completely stuck!

    Any experts out there who could help please?

    Thanks

    Bini

    #2
    I'm not sure I understand what "the scripts page is viewable" means but you can prevent a page from being viewable using a .htaccess file.

    Achieving and certifying pci compliance is not easy and most small businesses find it's best to use a psp.

    Mike
    -----------------------------------------

    First Tackle - Fly Fishing and Game Angling

    -----------------------------------------

    Comment


      #3
      Originally posted by Mike Hughes View Post
      I'm not sure I understand what "the scripts page is viewable" means but you can prevent a page from being viewable using a .htaccess file.

      Achieving and certifying pci compliance is not easy and most small businesses find it's best to use a psp.

      Mike
      Hi Mike, thanks for getting back to me - basically the following page should not be viewable by general public - http://www.extrememuscle.co.uk/scripts/

      Where would i place the .htaccess file please?
      I know basic HTML and CSS, but use Actinic as i dont need to do much coding, so your help would be really appreciated!

      Thank you

      Kind Regards
      Bini

      Comment


        #4
        This should be blocked as standard and typically is on a unix server. I suspect you could be on a windows server which I have no experience of.

        Your best bet is to get your web host to set this in the server configuration. If the won't help you then you either need to learn some new skills or find a more helpful web host. Achieving and maintaining pci compliance isn't easy and can be technically challenging. One of the reasons most small businesses use a psp.

        Mike
        -----------------------------------------

        First Tackle - Fly Fishing and Game Angling

        -----------------------------------------

        Comment


          #5
          If you're downloading cc details then pci compliance will extend to your local computers and network as well.

          Regarding your scripts directory you might get away with putting a default html page in the scripts directory.

          Comment


            #6
            Thanks for the reply guys, really appreciate it.

            Duncan, creating a default html, do i just make a blank page and put into scripts folder or do i need to put some code into it?

            Mike, by using just a PSP, would that then mean i wont need the scripts folder?

            Thank you

            Bini

            Comment


              #7
              Originally posted by binisingh View Post
              ...
              Duncan, creating a default html, do i just make a blank page and put into scripts folder or do i need to put some code into it?
              ...
              A blank pahe will stop general viewing of the directory

              Comment


                #8
                Thank you Duncan,

                I've done a quick search on how to create .htaccess file and come across this link which will create the text for you, could someone please give me some assistance on which options i need to tick off so that it will work and still allow Actinic to work correctly please?

                http://htaccesser.apacheblog.de/index-nojs.php

                Thank you

                Kind Regards

                Bini

                Comment


                  #9
                  are you hosted on a unix or windows server? AFAIK .htaccess files only work on unix servers.

                  Mike
                  -----------------------------------------

                  First Tackle - Fly Fishing and Game Angling

                  -----------------------------------------

                  Comment


                    #10
                    unfortunately I'm on a window's server.

                    Comment


                      #11
                      I thought you were, but there's now a redirect on the link you gave above so I assume it's fixed?

                      Mike
                      -----------------------------------------

                      First Tackle - Fly Fishing and Game Angling

                      -----------------------------------------

                      Comment


                        #12
                        Hi Mike,

                        I did resolve it with the deafult,html, but realised, for whatever reason, the Paypal link has now stopped working!

                        Im getting the following error message:

                        CGI Error

                        The specified CGI application misbehaved by not returning a complete set of HTTP headers.

                        --------

                        This is when i add a product, go to check out and select paypal.

                        Can anyone please help?

                        Kind Regards

                        Bini

                        Comment

                        Working...
                        X