Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default PCI Compliance

    Hello,

    We were informed earlier about some issue with PCI compliance testing and was hoping some clarification about these issues. The mainly concern mail ports and SSL port 443:
    Code:
    Protocol Port Program Risk Summary
    
    TCP 25 smtp 8 Synopsis : An open SMTP relay is running on this port. Description : 
    The remote SMTP server is insufficiently protected against relaying. This means that it 
    allows spammers to use your mail server to send their mails to the world, thus wasting 
    your network bandwidth. Solution: Reconfigure your SMTP server so that it cannot be 
    used as a relay any more. Risk Factor: High  / CVSS Base Score : 
    7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C) [More] 
    [Hide]
    TCP 465 urd 8 Synopsis : An open SMTP relay is running on this port. Description : 
    The remote SMTP server is insufficiently protected against relaying. This means that it 
    allows spammers to use your mail server to send their mails to the world, thus wasting 
    your network bandwidth. Solution: Reconfigure your SMTP server so that it cannot be 
    used as a relay any more. Risk Factor: High  / CVSS Base Score : 
    7.8 (CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C) [More] 
    [Hide]
    TCP 443 https 5 Synopsis : It is possible to retrieve file backups from the remote web server. 
    Description : By appending various suffixes (ie: .old, .bak, ~, etc...) to the names of various 
    files on the remote host, it seems possible to retrieve their contents, which may result in 
    disclosure of sensitive information. Solution: Ensure the files do no contain any sensitive information, 
    such as credentials to connect to a database, and delete or protect those files that should not be 
    accessible. Risk Factor: Medium  / CVSS Base Score : 5.0 (CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N) [More]
    Is there anything we can do resolve these issues? I believe these ports are used by the Cpanel Control panels also.

    Thank you,
    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Well to fix the 3rd one, you can do that with mod_security.

    For the first two, those may be false positives, which scanner did you use?

  3. #3
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    Yes we do have mod security installed, default install from EasyApache.

    I had the Cpanel Tech people double check these issues with the mail ports and they found no problems, no open relays. These PCI scans are pretty much bogus and a real pain!!

    thx's
    Mike

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  4. #4
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    Quote Originally Posted by mickalo View Post
    Yes we do have mod security installed, default install from EasyApache.

    I had the Cpanel Tech people double check these issues with the mail ports and they found no problems, no open relays. These PCI scans are pretty much bogus and a real pain!!

    thx's
    Mike
    And it appears, you've been at it for a while now too.


    PCI Compliance

Similar Threads & Tags
Similar threads

  1. PCI Compliance
    By richardsonchris in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-21-2011, 08:04 AM
  2. PCI Compliance
    By mickalo in forum E-mail Discussions
    Replies: 2
    Last Post: 08-20-2009, 12:34 PM
  3. PCI Compliance
    By FourMat in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-19-2009, 10:09 AM
  4. pci compliance help
    By EWD in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 05-29-2008, 11:34 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube