Penetration Testing mailing list archives

Re: reporting a web site breach


From: "David Glosser" <david.glosser () gmail com>
Date: Thu, 16 Oct 2008 19:46:36 -0400

More like if they process, transmit, or store Credit Cards Numbers.
There are at least two problems Jason pointed out: 1)the credit card
numbers are stored unencrypted and 2)the CVV number is stored as well.

But beyond the "contact us" page, I didn't see any information on the
pcisecuritystandards web site.
Aren't they just a standards organization?


On Thu, Oct 16, 2008 at 5:00 PM, Anthony Cicalla
<anthony.cicalla () gmail com> wrote:
if they process credit card numbers get in touch with the pci data
security council.


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------


Current thread: