in reply to Re: Re: Credit Card Billing
in thread Credit Card Billing
Something like:
Internet =====> Firewall ===>
DMZ Web Server ==> Firewall ==>
Seriously Locked Down CC Processer
The 'CC Processer' box should be running no services at
all, and listening on only one socket. This socket should
accept inbound transactions and return an ack/nack, and
nothing else. This would mean that administration, key changes, logging in, etc, would have to be done at the console. The web server should only have CC number while
they are in transit, and should never write them to disk.The folks at VISA have a pretty decent summary of what should be done to protect machines with CC data. ( It's a bit lacking on implementation details, but still good.) See: The VISA CISP Tech Info page.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Re: Re: Credit Card Billing
by metadoktor (Hermit) on Jan 05, 2002 at 22:33 UTC |