nealdxmhost
Verified User
Got hit with another PCI compliance headache the other day and I have been going round and round trying to figure what I am doing wrong to resolve this.
Anyhow this is the general synopsis of what I got from McAfee on this problem;
Any ideas?????
Anyhow this is the general synopsis of what I got from McAfee on this problem;
FTP supporting clear text authentication, where the remote FTP server allows the user's name and password to be transmitted in clear text, which may be intercepted by a network sniffer, or a man-in-the-middle attack.
The General Solution they recommend: switch to SFTP (part of the SSH suite) or FTPS (FTP over SSL/TLS). In the latter case, configure the server such that control connections are encrypted.
Any ideas?????