I’ve now had several e-commerce sites security audited by a firm called Security Metrics, which is hired by Card Services (the umbrella group for Visa/Mastercard). I’ve been able to remedy the SQL injection issues they found, but they are failing because the servers still accept SSL 2 connections. If I can’t fix this, I’m going to have to take this site off Jodo servers, and also two other sites I’ve got in development.
PCI compliance is an absolute requirement - if you don’t pass these tests they can assess large fines and will cancel merchant accounts. I’ve been in contact with Jodo, and they can’t disable SSL 2 on the affected server. Still waiting to her if there is a server configured without SSL2 that I can move to. But I’m just wondering if anyone else has come across this? Why would someone still need SSL2? And is there a way to test if a server accepts SSL2 connections?
thanks