Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Full Disclosure: Re: Hardcoded Keys

Re: Hardcoded Keys

From: Gary E. Miller <gem_at_rellim.com>
Date: Thu, 4 Sep 2008 15:38:29 -0700 (PDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Yo All!

> I believe it almost never happens. As I understand the card association
> rules, the merchant has to hang on to the data for refund purposes.

Nope, all you need to generate a refund is the original transaction ID. At
least with the processors I use.

You can get the PCI requirements here:

https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml

You are allowed to store the Card number, name and expiration date.
Appendix B allows you to store that unencrypted.

You are not allowed to store the mag stripe, CVC2 or PIN.

RGDS
GARY
- ---------------------------------------------------------------------------
Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97701
        gem_at_rellim.com Tel:+1(541)382-8588

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFIwGNoBmnRqz71OvMRAvHmAKCepmVQ4F5fOWdxU5VOD9gTMYW3rACcCWfe
Fv3+09X/t92G6Du76Z9Bocs=
=YoK0
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Sep 04 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]