Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Apr 2008
    Location
    sanctum sanctorum
    Posts
    152

    Default PCI compliance and FileETags

    I have been told that CPanel® recommends Apache FileETags directive is set to None for PCI compliance. Can you please tell me the reasoning behind this interpretation of the standard.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2007
    Posts
    139

    Default Pci Companies

    Some pci companies want the FileETags set to none. This is more security through obscurity than actual protecting the server in my mind but it is generally easier to just disable it then argue with the pci company every time. While not every pci company looks for this, none of them are going to complain if it is set to none.

  3. #3
    Member
    Join Date
    Apr 2008
    Location
    sanctum sanctorum
    Posts
    152

    Default

    Quote Originally Posted by sirdopes View Post
    Some pci companies want the FileETags set to none. This is more security through obscurity than actual protecting the server in my mind
    This is not even security through obscurity. What exactly is is disclosed by setting
    Code:
    FileETag MTime Size
    The last modification date and the size. Totally absurd as those are two fields sent by server anyway as response headers Last-Modified and Content-Length.

    Even when INode is used to generate the tag, a sweeping fail is a fundamental misunderstanding of an old and no longer relevant issue [1, 2, 3].
    Quote Originally Posted by sirdopes View Post
    it is generally easier to just disable it then argue with the pci company every time. While not every pci company looks for this, none of them are going to complain if it is set to none.
    I am with you there. Still, someone should point out their incompetence if they don't even understand what they are certifying. Monkey see, monkey do.

    [1] Apache HTTP Server MIME message boundaries information disclosure
    [2] Apache Web Server ETag Header Information Disclosure Weakness
    [3] Apache ETag Inode Information Leakage

Similar Threads & Tags
Similar threads

  1. PCI Compliance
    By mickalo in forum Security
    Replies: 3
    Last Post: 12-15-2009, 12:41 PM
  2. PCI Compliance
    By mickalo in forum E-mail Discussions
    Replies: 2
    Last Post: 08-20-2009, 12:34 PM
  3. PCI Compliance
    By FourMat in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-19-2009, 10:09 AM
  4. pci compliance help
    By EWD in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 05-29-2008, 11:34 PM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube