0
PCI Compliance and sessionid

/t5/coldfusion-discussions/pci-compliance-and-sessionid/td-p/363562
Jun 05, 2008
Jun 05, 2008
Copy link to clipboard
Copied
A recent scan of an ecommerce site I've developed and hosted
on a shared server at CrystalTech has failed a PCI compliance test
recently. It previously passed them.
The report says that sessionids are predictable and therefore insecure. This threatens my relationship with the credit card companies. The good folks at CrystalTech have not been helpful yet. Is anyone familiar with this issue or have valuable thoughts?
Interestingly, Securitymetrics calls it "Allaire Coldfusion". Man, are they out of date.
The report says that sessionids are predictable and therefore insecure. This threatens my relationship with the credit card companies. The good folks at CrystalTech have not been helpful yet. Is anyone familiar with this issue or have valuable thoughts?
Interestingly, Securitymetrics calls it "Allaire Coldfusion". Man, are they out of date.
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting.
Learn more
Advocate
,
LATEST
/t5/coldfusion-discussions/pci-compliance-and-sessionid/m-p/363563#M32602
Jun 10, 2008
Jun 10, 2008
Copy link to clipboard
Copied
It's a faulty report. Refer them to the following URL:
http://livedocs.adobe.com/coldfusion/8/htmldocs/help.html?content=sharedVars_06.html
http://livedocs.adobe.com/coldfusion/8/htmldocs/help.html?content=sharedVars_06.html
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting.
Learn more

