<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: PCI ASV re-cert test</title>
    <link>http://blog.clearnetsec.com/articles/2008/05/31/pci-asv-re-cert-test</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>PCI ASV re-cert test</title>
      <description>&lt;p&gt;Last year I spent hours of manual effort probing the Mastercard PCI test environment to discover all the vulnerabilities I could find.  I was truly stressed.  I was sure Mastercard setup vulnerabilities which were not discoverable by automated scanners.  I was also excited:  I wanted to compete and discover more vulnerabilities than the next guy.
&lt;/p&gt;
&lt;p&gt;
How na&#239;ve huh?  Well this year I did nothing.  A colleague hit the Qualys &#8220;scan&#8221; button.  
&lt;/p&gt;
&lt;p&gt;
Screw going above the call of duty - I didn&#8217;t have to do any work and that was great.  Hail PCI!
&lt;/p&gt;

</description>
      <pubDate>Sat, 31 May 2008 10:53:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:7b1d0454-69ec-4163-bcd0-e455100ff1e1</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/05/31/pci-asv-re-cert-test</link>
      <category>Tate Hansen</category>
      <category>ClearNet Security</category>
      <category>ClearNet</category>
      <category>PCI</category>
      <category>ASV</category>
      <category>security</category>
      <category>recertification</category>
      <category>mastercard</category>
      <category>Qualys</category>
    </item>
  </channel>
</rss>
