Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
0

PCI Compliance and sessionid

Guest
Jun 05, 2008 Jun 05, 2008
A recent scan of an ecommerce site I've developed and hosted on a shared server at CrystalTech has failed a PCI compliance test recently. It previously passed them.

The report says that sessionids are predictable and therefore insecure. This threatens my relationship with the credit card companies. The good folks at CrystalTech have not been helpful yet. Is anyone familiar with this issue or have valuable thoughts?

Interestingly, Securitymetrics calls it "Allaire Coldfusion". Man, are they out of date.
499
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Advocate ,
Jun 10, 2008 Jun 10, 2008
LATEST
It's a faulty report. Refer them to the following URL:

http://livedocs.adobe.com/coldfusion/8/htmldocs/help.html?content=sharedVars_06.html

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources