ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    PCI compliance scan fail

    IT Discussion
    pci compliance
    4
    5
    689
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • WrCombsW
      WrCombs
      last edited by

      First and foremost, I am an IT intern, Still super new and trying to impress my boss.

      I have a site that failed a PCI compliance scan in the past, after we did our fix last time (according to my team: they reset the firewall configuration and took the firewall back to the site. )

      The site then again failed the Scan again just a few days ago. We think they may have another computer hooked up on the firewall that is causing a problem.
      We provide a back office server along with Point of Sale terminals for the front of house.

      What steps can I take to fix ?

      They are failing at :
      -Basic Authentication over HTTP
      -Web page Transmits login credentials without encryption

      Any input would be appreciated.

      1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch
        last edited by

        You have something answering on port 80 turn it off

        KellyK scottalanmillerS 2 Replies Last reply Reply Quote 3
        • KellyK
          Kelly @JaredBusch
          last edited by

          @jaredbusch said in PCI compliance scan fail:

          You have something answering on port 80 turn it off

          Just to expand on this a bit, you're going to want to make sure that port 80 is blocked on the firewall. Most firewalls open by exception, so that means that port 80 has been specifically opened. Or the firewall is a terrible one and is itself allowing access to it on port 80.

          WrCombsW 1 Reply Last reply Reply Quote 0
          • WrCombsW
            WrCombs @Kelly
            last edited by

            @kelly @JaredBusch
            Thank you

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @JaredBusch
              last edited by

              @jaredbusch said in PCI compliance scan fail:

              You have something answering on port 80 turn it off

              It's literally that simple. Both turn off whatever is talking on 80, and block 80 on the firewall, too.

              1 Reply Last reply Reply Quote 1
              • 1 / 1
              • First post
                Last post