Announcement

Collapse
No announcement yet.

Pci 4.0 scan fail

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Pci 4.0 scan fail

    Ok my security metrics scan has failed on the following (hosted by Sellerdeck if relevant) - any hints apprecited

    Being hosted with Sellerdeck maybe relevant for the mail fails I guess as it's through their servers.

    Edit, Raised a support ticket as all the fails seem to be related to hosting. (Sellerdeck).

    Thanks Ed


    Click image for larger version  Name:	FAILS.png Views:	0 Size:	58.4 KB ID:	557537
    Attached Files
    https://www.harrisontelescopes.co.uk/

    Ed Harrison - Menmuir Scotland

    #2
    A week later and nothing from support, just fail reminders from security metrics...
    https://www.harrisontelescopes.co.uk/

    Ed Harrison - Menmuir Scotland

    Comment


      #3
      Have you downloaded the scan report and sent this as an attachment to support for information / attention concerning the fails flagged up?

      The report should include an explanation for each of the fails with suggestions on sources for guidance on action needed to resolve them.
      Martin
      Mantra Audio

      Comment


        #4
        Hi Martin,.
        Yes all done a week ago, hopefully they'll fix it soon, surely I can't be the first with sellerdeck hosting to have a PCI scan?

        It worries me that the hosting I pay a lot for in the 365 package is not currently PCI compliant.
        https://www.harrisontelescopes.co.uk/

        Ed Harrison - Menmuir Scotland

        Comment


          #5
          Hi Ed
          Did you get the scan fails resolved and were they all related to hosting?
          Also were these new fails that were not flagged up by a previous Security Metrics 90 day scan run?
          Martin
          Mantra Audio

          Comment


            #6
            Unfortunately it is an issue related to Sellerdeck hosting and support are aware but have said it could be some time.

            This was my first scan in a few years as using PayPal it wasn't required until PCI 4.0 came in.

            I am concerned as it is a Month now without it being resolved.
            https://www.harrisontelescopes.co.uk/

            Ed Harrison - Menmuir Scotland

            Comment


              #7
              The first two should be resolved fast (do a quick Google and you can see the fixes are simple)

              but the 3rd one... we used to be on a shared host (not Sellerdeck) and our host would not change that setting
              as it would affect customers with versions of Sellerdeck/Actinic that doesn't support Secure FTP.

              (You can do a ip search that shows what domains are hosted on it - can give you an idea of the situation)

              Comment


                #8
                Thank you, I pay a lot for the complete 365 package from Sellerdeck covering hosting and support so hopefully they will resolve this soon, I am concerned being non compliant.

                That said I do think the whole PCI and GDPR thing is blown up, it's become an industry in itself.
                https://www.harrisontelescopes.co.uk/

                Ed Harrison - Menmuir Scotland

                Comment


                  #9
                  Originally posted by EdHarrison View Post
                  Thank you, I pay a lot for the complete 365 package from Sellerdeck covering hosting and support so hopefully they will resolve this soon, I am concerned being non compliant.

                  That said I do think the whole PCI and GDPR thing is blown up, it's become an industry in itself.
                  Wondering if a Sellerdeck site, upto date version , on Sellerdeck hosting, using ClearAccept as sole payment gateway would be compliant out of the box?

                  www.devotedly-discus.co.uk

                  Comment


                    #10
                    I don't believe so as their hosting is the issue
                    https://www.harrisontelescopes.co.uk/

                    Ed Harrison - Menmuir Scotland

                    Comment


                      #11
                      I'm sure they can... It's quite simple...

                      They can setup/move everyone using v18 Sellerdeck onto SecureFTP / PCI compliant / up-to-date server(s)
                      - if the IP address can't be maintained, then just the DNS record(s) needs updating

                      I seem to have this bookmarked
                      https://search.dnslytics.com/search?...&q=81.29.88.81
                      I think the IP was the Sellerdeck 365 server we used to be on

                      Comment

                      Working...
                      X