Re: PCI Compliance

2010-03-18 Thread Barney Desmond
On 18 March 2010 23:59, J. Roeleveld wrote: > Does this mean that the service-desk of companies are not compliant either? Hehe, in a way. Social engineering is thankfully(?) outside the scope of PCI-DSS compliance. > 1) Check in phonebook for number of VISA credit card service desk > 2) Call lis

Re: PCI Compliance

2010-03-18 Thread J. Roeleveld
On Thursday 18 March 2010 13:26:43 Barney Desmond wrote: > On 18 March 2010 21:57, Jonathan Tripathy wrote: > 3. We read the report, and find things like "server exposes its > hostname in the greeting banner", or "server appears to allow the use > of the VRFY command". Does this mean that the

Re: PCI Compliance

2010-03-18 Thread Barney Desmond
On 18 March 2010 21:57, Jonathan Tripathy wrote: > Any ideas on how to set up an "SMTP Proxy Server" to attain PCI Compliance? > I literally need postfix to just pass through mail to our ISP's smtp server. > We would then set outlook to use this local smtp proxy server. I work for a hosting compa