• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
0

PCI Compliance and sessionid

Guest
Jun 05, 2008 Jun 05, 2008

Copy link to clipboard

Copied

A recent scan of an ecommerce site I've developed and hosted on a shared server at CrystalTech has failed a PCI compliance test recently. It previously passed them.

The report says that sessionids are predictable and therefore insecure. This threatens my relationship with the credit card companies. The good folks at CrystalTech have not been helpful yet. Is anyone familiar with this issue or have valuable thoughts?

Interestingly, Securitymetrics calls it "Allaire Coldfusion". Man, are they out of date.

Views

472

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Advocate ,
Jun 10, 2008 Jun 10, 2008

Copy link to clipboard

Copied

LATEST
It's a faulty report. Refer them to the following URL:

http://livedocs.adobe.com/coldfusion/8/htmldocs/help.html?content=sharedVars_06.html

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources
Documentation