Find Jobs
Hire Freelancers

PCI compliance vulnerabilitys - open to bidding

$30-250 USD

Anulat
Data postării: aproape 10 ani în urmă

$30-250 USD

Plata la predare
Hi, We have had a Trustwave PCI scan completed on our server and it has flagged up a few vunerability's, we require these fixing and to perform a scan that passes upon completion. Here is our server specification; [login to view URL] economic hosting linux Here is the list of issues we require fixing; #1. Unencrypted Communication Channel Accessibility The service running on this port appears to make use of a plaintext (unencrypted) communication channel. The PCI DSS forbids the use of such insecure services/protocols. Unencrypted communication channels are vulnerable to the disclosure and/or modification of any data transiting through them (including usernames and passwords), and as such the confidentially and integrity of the data in transit cannot be ensured with any level of certainty. Transition to using more secure alternatives such as SSH instead of Telnet and SFTP in favor of FTP, or consider wrapping less secure services within more secure technologies by utilizing the benefits offered by VPN, SSL/TLS, or IPSec for example. Also, limit access to management protocols/services to specific IP addresses (usually accomplished via a "whitelist") whenever possible. #[login to view URL] Keyboard-Interactive Authentication Username Enumeration The remote host is running the secure-shell (SSH) service, and allows for authentication via the "keyboard-interactive" method. This method passes authentication off to a third party, who will provide a prompt (often "Password:") that is sent back to the SSH client. The remote SSH service varies its response dependent on the username that is provided, making it possible to enumerate usernames on the remote host. This variance is often due to the use of one-time password (OTP) authentication mechanisms such as S/Key and OPIE, which require a random challenge to be presented to those authenticating. Often in these setups, only those users that are configured to use one-time passwords will be prompted with a random challenge. Thus, it is possible to positively identify those usernames that are configured to use one-time password authentication. A known vulnerability in pam_ssh (CVE-2009-1273) 1.92 and earlier may trigger this finding, as pam_ssh would report a different prompt depending on if the username was valid or not. It is recommended that the challenge authentication mechanism be replaced with something that does not reveal the presence of user accounts. Two-factor authentication mechanisms using security tokens, for example, do not require a revealing challenge. Consult your documentation for the affected SSH service for more information on modifying its authentication mechanisms. If pam_ssh is the culprit, then check with your vendor for a patch for CVE-2009-1273. CVE-2007-2243 CVE-207-2768 CVE-2009-1273 #[login to view URL] web server running on this host allows attackers to probe for user names via requests for user home pages (e.g., http://host/~username). Many different types of web servers exhibit this behavior, but it is most commonly associated with Apache HTTP Server. Configure the HTTP server to specify the same error documents for both 403 (Forbidden) and 404 (Page Not Found) responses. Additionally, if Apache is being used, the UserDir directive should be disabled in the Apache configuration file ([login to view URL]). CVE-2001-1013 Thanks, Phillip
ID-ul proiectului: 6031937

Despre proiect

9 propuneri
Proiect la distanță
Activ: 10 ani în urmă

Vrei să câștigi bani?

Avantajele de a licita pe platforma Freelancer

Stabilește bugetul și intervalul temporal
Îți primești plata pentru serviciile prestate
Evidențiază-ți propunerea
Te înregistrezi și licitezi gratuit pentru proiecte
9 freelanceri plasează o ofertă medie de $154 USD pentru proiect
Avatarul utilizatorului
Hi Few days ago I finished project PCI DSS Secure for WHM/cPanel and get good review. I can do same for your Plesk server. You got a 100% secured server with gurantee success scan PCI DSS. SSH root server & admin Plesk access is requied. You need own Server (Real/Virtual), not shared hosting.
$66 USD în 1 zi
4,8 (222 recenzii)
6,8
6,8
Avatarul utilizatorului
Hi Boss, I have ample experience in linux server administration, website migration, installation and configuration of custom software with security. I can do this project for you. You may please have a look on my profile for further information regarding me. Looking forward for a positive reply from your end. Regards, Minu Thomas https://www.freelancer.com/u/minuthomas.html
$105 USD în 1 zi
4,9 (116 recenzii)
6,3
6,3
Avatarul utilizatorului
Hi Phillip, I'm a Network and System Administrator. If provided root ssh/WHM access to your server, I can make it PCI compliant, I did this so many times before, my latest work is on subimods.com. Please see my feedback to evaluate my previous works, and shoot me your reply if you want to talk about this further. Regards, Aroel
$147 USD în 0 zi
5,0 (116 recenzii)
6,2
6,2
Avatarul utilizatorului
Hi , I can see you have tested your server's security with a plugin . I am here to help. I am a experienced Linux Server administrator with Cpanel/WHM/Plesk security and optimization. I can fix your SSH related vulnerabilities and apache mod_userdir problem . And for the first one you may need to buy a trusted SSL certifcate (I sell them) . Please let me know if looking to fix your server quickly . Thanks. Best Regards, Shahriar
$277 USD în 3 zile
5,0 (3 recenzii)
2,6
2,6
Avatarul utilizatorului
I have been working with a different network topologies. Network engineer and system administrator with 5+ years of hands-on experience. I am skilled linxu system administrator, with lot of experience in Linux(CentOS, Fedora core, Ubuntu). I have got working experience with: DNS, DHCP, NTP, HTTP, SNMP, SMTP, SMB, SCL, firewalls, NAT, VLAN, OSPF, RIP, Multicast routing; I am proficient in configuring Cisco routers and switchs, network designing and implementing. I have got working experience with: Switching and routing: security(ACL, IDS/IPS, RADIUS, VPN(sslvpn, IPsec vpn), monitoring, clouds, HA) Job History 1) Squid proxy setup 2) Fix installation of VNC and Serviio on an Ubuntu machine 3) Linux admin 4) Install Apache virtualhosts and fix Apache configuration 5) Setup VPN on my linux server 6) Some tasks on a linux server 7) Configuring Two Cisco routers programmed for a point to point 8) Setup FTP server on our Google compute Engine Linux machine 9) SSh key exchange 10) Script to change config file and send email with change on Linux skills Linux network administrator firewall VPN IPS TCP/IP Cisco perl C Apache, DNS, mail server, DHCP administration
$155 USD în 1 zi
0,0 (0 recenzii)
0,0
0,0
Avatarul utilizatorului
Dears, Kindly be informed that I'm VMware and Symantec specialist. I have a Master of Computer Science and Information Technology and Systems Engineering from WoodField University, USA. And a Bachelor of communication Engineering. Looking forward to work with you. Regards Mohamed
$90 USD în 3 zile
0,0 (0 recenzii)
0,0
0,0

Despre client

Steagul UNITED STATES
Santa Fe Springs, United States
5,0
1
Metoda de plată a fost confirmată
Membru din iun. 4, 2014

Verificarea clientului

Mulțumim! Ți-am trimis prin e-mail linkul pe care trebuie să-l accesezi pentru a revendica creditul gratuit.
A apărut o eroare la trimiterea e-mailului. Încearcă din nou.
Utilizatori înregistrați Totalul proiectelor postate
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
Se încarcă previzualizarea
S-a oferit permisiunea de depistare a locației.
Ți-a expirat sesiunea pentru conectare sau te-ai deconectat. Conectează-te din nou.