Announcement

Collapse
No announcement yet.

Security clearance of site

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Security clearance of site

    I am using Actinic Business on v7.0.7.0.0.0 and have my site hosted by a Actinic Business partner with a separate https server handling the checkout pages.

    My bank require Security Metrics to validate security settings on the site and it is currently failing on one last hurdle with the following failure report issued by the Security Metrics tests


    " Security Vulnerabilities: TCP Protocol http/https
    Possible injection http://www.my domain.com/cgi-bin/ss00 0002.pl?PRODREF=%3Cxss%3Ealert%28%27XSS%27 %29%3C%2Fvulnerable%3E&NOLOGIN=1 ("<xss>alert('XSS')</vulnerable>") ; Possible injection http://www.mydomain.com/cgi-bin/ss00 0002.pl?PRODREF=%3Cxss%3Ealert%28%27XSS%27 %29%3C%2Fvulnerable%3E&NOLOGIN=1 ("<xss>alert('XSS')</vulnerable>") ; Possible injection http://www.mydomain.com/cgi-bin/ss00 0002.pl?PRODREF=%3Cxss%3Ealert%28%27XSS%27 %29%3C%2Fvulnerable%3E&NOLOGIN=1 ("<xss>alert('XSS')</vulnerable>") ; Possible injection http://www.mydomain.com/cgi-bin/ss00 0002.pl?PRODREF=%3Cxss%3Ealert%28%27XSS%27 %29%3C%2Fvulnerable%3E&NOLOGIN=1 ("<xss>alert('XSS')</vulnerable>") ; Possible injection http://www.mydomain.com/cgi-bin/ss00 0002.pl?PRODREF=%3Cxss%3Ealert%28%27XSS%27 %29%3C%2Fvulnerable%3E&NOLOGIN=1 ("<xss>alert('XSS')</vulnerable>") ; Possible injection http://www [More] .... "

    Can anyone please help with advice as to whether there is a patch or something I need to get applied, business setting to change etc or is this a security gap in v7? Are there some settings my server host needs to change as they haven't come accross this before?

    Thanks


    #2
    If you are downloading credit card details for your own offline processing (via the https server) then I doubt you will ever get compliance.

    If you are using a PSP to process the credit card details then you do not need to be compliant - your PSP does.

    There are a number of recent forum posts relating to this. Search for them and have a read all about it.

    Comment


      #3
      And security metrics actually cause more problems than they solve, they dont understand what they are testing and will test a site that does ot need testing.

      If you dont process credit cards or collect the details then you dont need to be tested.

      As duncan said this is down to your psp, worldpay, protx e.t.c are already compliant and are the best options, getting actinic to ever be just aint worth the money IMHO

      Comment


        #4
        As always, search is your friend.

        http://community.actinic.com/showpos...6&postcount=24

        Mike
        -----------------------------------------

        First Tackle - Fly Fishing and Game Angling

        -----------------------------------------

        Comment


          #5
          Thanks for your help and advice. I had spent time searching but not used PCI in the search.... how dumb!

          Have just looked through the thread and see their are some patches to try loading on 7.0.7 for cross scripting issues

          Comment


            #6
            Hi Nigel. I searched on 'security metrics' which seemed to work well.

            I think you might need to contact Actinic support to get access to the security patches.

            Mike
            -----------------------------------------

            First Tackle - Fly Fishing and Game Angling

            -----------------------------------------

            Comment

            Working...
            X