• Home
  • About George
  • Contact Me
Blue Orange Green Pink Purple

PCI Compliance and Portcullis

Posted in ColdFusion. on Tuesday, November 10th, 2009 by George Tags: ColdFusion, PCI Compliance
Nov 10

So we’ve been doing a little bit of PCI Compliance work here at the office. One of the things that we found that really helped us out was a program called Portcullis – http://www.codfusion.com/blog/post.cfm/portcullis-cfc-filter-to-protect-against-sql-injection-and-xss. I suppose it’s not a full program, but a CFC to assist in how you do your security. We used it to help secure a site and meet our requirements. Much less expensive than some of the other web application firewalls out there, since it’s free :)

2 Comments

  1. Joel Richards on December 19th, 2009

    Hi George–
    I just implemented a portcullis on a site that was failing PCI compliance tests due to cross-site scripting vulnerabilities and it cleared that issue right up.
    My site is still failing because the server it’s hosted on uses coldfusion session management, not J2EE session management. I asked the host to turn on J2EE session variables, but they said they can’t. CF_token is set as a UUID, so I’d think this would pass muster, but it’s not. Have you run into this issue? Do you have any ideas?
    thanks,
    Joel

  2. George on January 19th, 2010

    We actually did run into this and we were able to show our compliance company that since the CFToken is never used without the CFID it truly is a unique and random generation. They were able to add an exception for this to the compliance process.



Leave a Reply

Web Development By George

  • About
    About me. Edit this in the options panel.
  • Photo Stream
  • Categories
    • ColdFusion
    • coldspring
    • Databases
    • Design
    • Flash
    • Flex
    • Internet
    • JavaScript
    • jQuery
    • Model-Glue
    • Personal
    • Subversion
    • Uncategorized
    • YUI
  • Recent Articles
    • Radios and JQuery and IE8
    • Coldfusion, Flex, and SSL
    • Leaving it to the Experts
    • CFAjaxProxy Problems or RTFM
    • I love the Internet
    • Interesting ColdFusion Survey
  • Archives
    • November 2011
    • May 2011
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • November 2009
    • October 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
  • Search




Add to Technorati Favorites

  • Home
  • About George
  • Contact Me

© Copyright Web Development By George. All rights reserved.
Designed by FTL Wordpress Themes brought to you by Smashing Magazine

Back to Top