Web Hosting Forum | Lunarpages
News: November 3, 2008 - Enter Your URL in to WIN the November Site of the Month Award!
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
November 18, 2008, 12:04:08 PM


Login with username, password and session length


Pages: [1]   Go Down
  Print  
Author Topic: Anyone certified by VISA on a shared server?  (Read 845 times)
sb
Pong! (the videogame) Master
*****
Offline Offline

Posts: 29


« on: April 04, 2006, 06:38:12 AM »

I'm going through the steps to accept credit cards on my online store.

For VISA/MC/AMEX to allow this, I must achieve PCI certification, which involves running a security assessment on my site.  The first run failed with about 8 Sev 3 failures.

Lunarpages techsupport says they can fix about half of those, but not all since it is a shared server.  They advise that I should move to a dedicated server @$99/mth.  Quite a LARGE step from the $7.95/mth I'm paying now.

I'm wondering anyone on a shared server here has achieve PCI cert., and if so, how?

sb.
Logged
sb
Pong! (the videogame) Master
*****
Offline Offline

Posts: 29


« Reply #1 on: April 06, 2006, 05:32:15 PM »

anyone?Huh  Of the 90,000 sites LP serves, not a single one is PCI certified on a shared server?
Logged
sb
Pong! (the videogame) Master
*****
Offline Offline

Posts: 29


« Reply #2 on: April 07, 2006, 09:21:02 AM »

 Sad

It appears as though I will be forced to move away from LP to get this done.

Perhaps Lunarpages should change the
"E-Commerce" bullet under the Shared Hosting Plan description to

"E-Commerce -- no credit cards"
Not looking forward to all the work involved in moving...

sb
Logged
Jay
MR-Disabled
Über Jedi
*
Offline Offline

Posts: 1560



« Reply #3 on: April 07, 2006, 09:44:03 AM »

PCI certification is not an industry standard that I know of.
What payment gateway, or merchant account are you using?

We have many thousands of customers using Payment gateways, e-commerce, and merchant accounts that have no such issues as you describe.

Please provide more details.


The top site that offers these 'hacker safe scans' show that only 70,000 websites are using this 'compliance'

As a note, this is quite the gimmick as far as I'm concerned, as with any properly protected database, trusted certificate (such as those we provide through Lunarpages) and well developed storefront, will never have any issues with a compromise.

There are many defenses in place and any site accessed via a trusted certificate (SSL / https protocol will be provided with various assurances that the information is safe.

As will the end user.

- Jay

« Last Edit: April 07, 2006, 09:49:23 AM by Jay » Logged

sb
Pong! (the videogame) Master
*****
Offline Offline

Posts: 29


« Reply #4 on: April 07, 2006, 10:05:00 AM »

My payment processor is Beanstream (beanstream.com).  These folks, FWIW, are VERY helpful and responsive.  They return my phone calls, and answer my questions usually within an hour. Thumbs Up

VISA will apparently not certify anyone (perhaps it's canada only?) without being certified by a PCI auditor.

The tests that are failing on lyra are:
- SSL Server Supports Weak Encryption Vulnerability 
-  SSL Server May Be Forced to Use Weak Encryption Vulnerability 
-  SSL Server Has SSLv2 Enabled Vulnerability 
-  SSL Server May Be Forced to Use Weak Encryption Vulnerability 
-  MySQL User-Defined Function Buffer Overflow Vulnerability 
-  Mail Server Accepts Plaintext Credentials 
-  UDP Source Port Pass Firewall (src port 53)

NOTE: My merchant vendor has informed me that if Lunarpages justifies these failures adequately, it is possible to approve the application anyway.  I've updated my ticket to ask for such justification.

They also informed me that if anyone else on my shared server (lyra) is PCI certified, a photocopy of that certification is all they would need to approve me.  Is this something LP could find for me?

"As a note, this is quite the gimmick as far as I'm concerned, as with any properly protected database, trusted certificate (such as those we provide through Lunarpages) and well developed storefront, will never have any issues with a compromise."

I think the point of this certification is to proove the "properly protected", "trusted", and "well developed" parts of your sentence.

Thanks for looking into this Jay!
sb.



Logged
jacknorth
Spacescooter Operator
*****
Offline Offline

Posts: 31



WWW
« Reply #5 on: July 22, 2008, 08:03:47 AM »

PCI certification is not an industry standard that I know of.


The top site that offers these 'hacker safe scans' show that only 70,000 websites are using this 'compliance'


- Jay



I believe that PCI is agreed to by the major players in the industry. that makes it an industry standard.

hacker safe and PCI are two different items. maybe LP could come up with a shared PCI certifiable environment for $14.99/month (or something like that)
Logged
MrPhil
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3473



« Reply #6 on: July 22, 2008, 08:38:08 PM »

NOTE: My merchant vendor has informed me that if Lunarpages justifies these failures adequately, it is possible to approve the application anyway.  I've updated my ticket to ask for such justification.

Have you searched all of Lunarforums.com for discussions on PCI? Do an advanced  search. There were some discussions on why Lunarpages accounts got a "false positive" on vulnerabilities in the PCI audits. This might be useful information on dealing with VISA.

Don't forget that other companies such as PayPal (and others) will be happy to accept credit cards on your behalf. You don't have  to have a merchant account and payment gateway.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.6 | SMF © 2006-2008, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM