<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: PCI ASV wonderland</title>
    <link>http://blog.clearnetsec.com/articles/2007/05/04/pci-misleading-racket</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>PCI ASV wonderland</title>
      <description>&lt;p&gt;
The world of the &lt;a href="https://www.pcisecuritystandards.org/tech/download_the_pci_dss.htm"&gt;PCI Security Standards&lt;/a&gt;, ASVs (Approved Scanning Vendors), and commercial scan vendors is, from my limited interactions, not exactly on the straight.  
&lt;/p&gt;
&lt;img src="http://blog.clearnetsec.com/files/panic1.jpg" align="right"&gt;
&lt;p&gt;
Having recently spent considerable time preparing, scanning, and writing reports with the explicit goal of becoming an ASV, I&#8217;m disturbed by my communications with all involved.
&lt;/p&gt;
&lt;p&gt;
It doesn&#8217;t help that the pass criteria to become an ASV is not clear.  Is it based on discovering all vulnerabilities on their test network?  A subset?  Which parts are subjectively reviewed?
&lt;/p&gt;
&lt;p&gt;
I like to use Qualys to baseline vulnerabilities, which a test representative caught as one of the tools we&#8217;d be using based on the source IP blocks for scanning.  He said something like &#8220;If you use Qualys, you&#8217;ll get 95% of what you need&#8221;.  From that I guessed the example web application would have vulnerabilities which would be missed by Qualys and other network-based tools.  As expected, that was true.  
&lt;/p&gt;
&lt;p&gt;
Fast forward.  We received feedback that our reports have not been reviewed because Qualys changed something recently causing expected results to be absent which PCI requires for passing.  The representative said &#8220;If you&#8217;d have scanned a month ago with Qualys, you&#8217;d have passed with flying colors&#8221;.  He added that they are in communication with Qualys to resolve the issue.
&lt;/p&gt;
&lt;p&gt;
Nevermind that Qualys was only one of the tools we used and we had added vulnerabilities not discovered by the popular free or commercial scanners.  It was clear the representative didn&#8217;t review the report, which he said as well (and may have done to protect us from an automatic failure -- even though our current pass status is pending).  But they would not reveal the gaps, which obviously makes it hard to understand what the problem is.  I appealed by mentioning I had added vulnerabilities not discovered by Qualys.  He then modified his previous statements by saying he in fact spot checked the reports and the items he was looking for were absent.  My gut reaction to all this:  bullshit.      
&lt;/p&gt;
&lt;p&gt;
The connections apparent make for a nice racket.  You pay lots of money to PCI.  PCI &#8220;communicates&#8221; with selective vendors to ensure all the vulnerabilities they expect to be discovered are discovered.  You pay money to the scan vendors.  And what about if you find additional vulnerabilities or a superset?  Sounds like they don&#8217;t check and don&#8217;t care.  I would think the idea behind all this is to make sure you are adding sufficient value to entities subject to PCI regulations (even if that means you didn't catch 100% of everything bad).  If passing simply means doing a blind Qualys scan when it works right (i.e. does what PCI wants), well then, you now know what to do to as an attacker -- just go after something Qualys doesn't check.
&lt;/p&gt;
&lt;p&gt;
So much for trusting this process and what it does to vet competent assessment companies. 


</description>
      <pubDate>Fri, 04 May 2007 11:52:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:c96d3aff-241d-40f3-982c-c6aa0a87ae6d</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/05/04/pci-misleading-racket</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>PCI</category>
      <category>ASV</category>
      <category>Qualys</category>
    </item>
    <item>
      <title>"PCI ASV wonderland" by LonerVamp</title>
      <description>&lt;p&gt;I&amp;#8217;ve always felt that things like PCI are all about paying lip service to security. Granted, lip service is better than the state of many companies, but in the end all this does is make other people money and increase the lowest common denominator. Which in turn means the lowest skills in crackerdom just have to inch up and we&amp;#8217;ll be back where we started. :\&lt;/p&gt;

&lt;p&gt;Hope you guys iron all that superficial junk out so you can provide your competent skills to companies who want more than just lip service and a handshake.&lt;/p&gt;</description>
      <pubDate>Sun, 06 May 2007 15:00:15 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:adf7b5c2-194b-4b3c-8669-670e610a45ac</guid>
      <link>http://blog.clearnetsec.com/articles/2007/05/04/pci-misleading-racket#comment-36</link>
    </item>
  </channel>
</rss>
