Find Jobs
Hire Freelancers

Making Adjustments to SSL Settings and FTP Permissions on Server(repost)

$30-5000 USD

已取消
已发布超过 13 年前

$30-5000 USD

货到付款
Hi there! Attempting another project with you, one for a different client and I believe a lot easier. :) Enjoyed working with you thus far. My client is receiving security warnings that they are not PCI compliant, from SecurityMetrics.com. My client's site is [login to view URL] and it's marked as NOT COMPLIANT with the PCI scan validation requirements on several different items. I believe it's a matter of adjusting SSL settings on server or FTP permissions, but I'm unfamiliar in this territory and don't want to make adjustments blindly. ## Deliverables Message from SecurityMetrics: "SecurityMetrics has determined that KATILADY EVENTS is NOT COMPLIANT with the PCI scan validation requirement for this computer. The computer **fails** because a risk of 4 or more was found." I have updated Wordpress...but it didn't seem to make a difference (I just did that yesterday and ran test again afterward). I can give you login info for the account so you can look at this more closely if you wish, if this is a job you are interested in. Example violations: "The remote web server contains several PHP scripts that are prone to SQL injection and cross-site scripting attacks. Description : According to its banner, the remote version of WordPress is vulnerable to various flaws which may allow an attacker to perform an HTML injection attack against the remote host or allow an attacker to execute arbitrary SQL statements against the remote database. See also : [[login to view URL] 84659][1] **Solution**: Upgrade to WordPress 1.2.2 or greater" "The remote web server contains several PHP scripts that are prone to SQL injection and cross-site scripting attacks. Description : According to its banner, the remote version of WordPress is vulnerable to various flaws which may allow an attacker to perform an HTML injection attack against the remote host or allow an attacker to execute arbitrary SQL statements against the remote database. See also : [[login to view URL] 84659][1] **Solution**: Upgrade to WordPress 1.2.2 or greater." "Description: Microsoft IIS Authentication Method Disclosed Severity: Area of Concern CVE: [CVE-2002-0419][2] Impact: An attacker could determine which authentication scheme is required for confidential web pages. This can be used for brute force attacks against known User IDs. Background: Microsoft IIS web servers support Basic and NTLM authentication. Determination of which authentication is used by a server may help with further intelligent attacks against the server or brute force password attacks. "
项目 ID: 2973286

关于此项目

远程项目
活跃13 年前

想赚点钱吗?

在Freelancer上竞价的好处

设定您的预算和时间范围
为您的工作获得报酬
简要概述您的提案
免费注册和竞标工作

关于客户

UNITED STATES的国旗
United States
5.0
28
会员自8月 27, 2010起

客户认证

谢谢!我们已通过电子邮件向您发送了索取免费积分的链接。
发送电子邮件时出现问题。请再试一次。
已注册用户 发布工作总数
Freelancer ® is a registered Trademark of Freelancer Technology Pty Limited (ACN 142 189 759)
Copyright © 2024 Freelancer Technology Pty Limited (ACN 142 189 759)
加载预览
授予地理位置权限。
您的登录会话已过期而且您已经登出,请再次登录。