New vulnvulnerability in Sears.com website reinforces the need for manual pen testing.
An interesting twist in the legal battle regarding the breach at CardSystems now has the PCI auditor on trial.
Insecure ciphers and protocols are still supported on a very large percentage servers we assess. We strongly advocate removing all insecure ciphers and protocols. The PCI Council nearly made it a requirement to disable SSLv2 – In the words of Maxwell Smart, “They missed it by THAT much”.
New Payment Processor System Hacked
Posted Under:
Discussion
This post was written by
Rick B. on February 25, 2009
Comments Off