Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

ASP.NET Forum


You are currently viewing our ASP.NET Forum as a guest. Please register to participate.
Login



Closed Thread
Failing PCI Standards. Need help please!!
Old 02-08-2011, 01:56 PM Failing PCI Standards. Need help please!!
vultren's Avatar
Super Spam Talker

Posts: 790
Name: Tony
Location: Seattle Washington
Trades: 1
I'm trying to help a friend and know nothing of this. So here is what I got, hopefully someone can help!
__________________

Please login or register to view this content. Registration is FREE

"Do or do not, there is no try"

Last edited by vultren; 02-13-2011 at 12:51 AM.. Reason: Take out code
vultren is offline
View Public Profile
 
 
Register now for full access!
Old 02-08-2011, 01:57 PM Re: Failing PCI Standards. Need help please!!
vultren's Avatar
Super Spam Talker

Posts: 790
Name: Tony
Location: Seattle Washington
Trades: 1
Editted out
__________________

Please login or register to view this content. Registration is FREE

"Do or do not, there is no try"

Last edited by vultren; 02-13-2011 at 12:52 AM.. Reason: Taking out code
vultren is offline
View Public Profile
 
Old 02-08-2011, 02:08 PM Re: Failing PCI Standards. Need help please!!
chrishirst's Avatar
Defies a Status

Posts: 43,961
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
First question WHY are you using an Access file as a database if you are handling credit card details??
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
View Public Profile Visit chrishirst's homepage!
 
Old 02-08-2011, 05:51 PM Re: Failing PCI Standards. Need help please!!
vultren's Avatar
Super Spam Talker

Posts: 790
Name: Tony
Location: Seattle Washington
Trades: 1
I did not code this. I think the code was written years ago too actually. I just have a friend who came to me asking if I could help and my area of expertise is not in this area... is the access file the cause of the SQL Injection?
__________________

Please login or register to view this content. Registration is FREE

"Do or do not, there is no try"
vultren is offline
View Public Profile
 
Old 02-08-2011, 06:38 PM Re: Failing PCI Standards. Need help please!!
chrishirst's Avatar
Defies a Status

Posts: 43,961
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
No, but Access files can be downloaded and read if the location in the site is exposed.

Are you collecting and storing credit card information on the site?
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
View Public Profile Visit chrishirst's homepage!
 
Old 02-08-2011, 07:40 PM Re: Failing PCI Standards. Need help please!!
vultren's Avatar
Super Spam Talker

Posts: 790
Name: Tony
Location: Seattle Washington
Trades: 1
Quote:
Originally Posted by chrishirst View Post
No, but Access files can be downloaded and read if the location in the site is exposed.

Are you collecting and storing credit card information on the site?
Yes, he collects credit card information and uses that information to process the payment.

What steps should I assist him in making it so he is PCI Compatible?
__________________

Please login or register to view this content. Registration is FREE

"Do or do not, there is no try"
vultren is offline
View Public Profile
 
Old 02-09-2011, 11:03 AM Re: Failing PCI Standards. Need help please!!
rolda hayes's Avatar
Wannabe Adventurer...

Posts: 973
Name: Darren
Location: England
Trades: 0
Apart from the more pressing issue of the Access database, it looks like the PCI fail may be to do with the search form;

Code:
<input type="text" size="15" maxlength="60" name="txtKeyword" id="txtKeyword" class="ActionInput" value="Search..." onfocus="doConditionalErase();">
Who is the PCI company running the scans?
__________________
I Just a test to see what happens...
Please login or register to view this content. Registration is FREE

"Let us be thankful for the fools. But for them the rest of us could not succeed..."
rolda hayes is offline
View Public Profile
 
Old 02-10-2011, 08:08 AM Re: Failing PCI Standards. Need help please!!
Extreme Talker

Posts: 246
Trades: 0
To prevent SQL injections use stored procedures (unless you decide to use Dynamic SQL inside the stored proc). This however won't help the fact that you guys are using an Access DB like Chrishirst has said. Use MS SQL, MySQL, DB2, Oracle any of these please rather than Access, especially since you are storing credit card information. Also, since what I see so far looks scary MAKE SURE YOU ARE ENCRYPTING THE CREDIT CARD INFO IN THE DATABASE!!!!!

Can you let us know what site this is so that we don't go there and buy something.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
stbuchok is offline
View Public Profile
 
Old 02-16-2011, 09:16 PM Re: Failing PCI Standards. Need help please!!
Experienced Talker

Posts: 39
Name: Josh Rasri
Location: Upstate NY
Trades: 0
No matter what database you're using I would think you would only store the billing information *just long enough to process it* -- then securely delete it. Don't store it for historical reasons or future customer use as it may fall into the wrong hands.
Also ensure any form submission data is being checked for validity especially if doing any type of dynamic SQL commands. When I say validity I mean that if numbers are to be entered, ensure they are numbers, set a max length to acceptable values, and strip and chars that can be used for sql injection attacks (search Google for ways to combat SQL injection - tons o' information).
__________________
John Rasri - GotLiveChat.com

Please login or register to view this content. Registration is FREE
Reseller/White Label Program
gotlivechat is offline
View Public Profile Visit gotlivechat's homepage!
 
Old 08-15-2011, 02:57 AM Re: Failing PCI Standards. Need help please!!
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,625
Location: UK
Trades: 1
OK a few things..

Has anyone who actually knows the standard looked at the setup?

A few things:
Yes, using an access DB isnt great however if you have locked it down correctly then you can still pass.
You shouldn't have CC details and Security code numbers in the same DB ( or the same server )
Your servers and networks should be separated by firewalls.
You need to use 2factor authentication to management networks, The management network also needs to be separated by firewalls.
You need policys on how to change and manage the firewalls and user accounts.
Etc etc etc.

If you failed a PCI test then they should say why!

Its not a cryptic School exam! its in their best interest to have you pass otherwise you run the risk of handing CC details out and causing no end of problems for you and others!
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
View Public Profile Visit lynxus's homepage!
 
Old 08-16-2011, 08:28 PM Re: Failing PCI Standards. Need help please!!
King Spam Talker

Posts: 1,090
Name: Paul W
Trades: 0
PCI examinations and judgements vary wildly but even so your friend should have been given a detailed report outlining good and bad points of the whole setup (and that means everything from webserver config to coding standards). Some will be meaningful, some bull**** to persuade people that PCI and associated businesses are kosher, but you still have to follow it to keep accepting payments, unless of course you go the other way and hand off the card-handling side to another agency.
__________________
Great music:
Please login or register to view this content. Registration is FREE



Please login or register to view this content. Registration is FREE
PaulW is offline
View Public Profile
 
Closed Thread     « Reply to Failing PCI Standards. Need help please!!
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.41933 seconds with 11 queries