Mcafee PCI 合规性在会话 ID cookie 上失败?
我正在尝试为我的网站获取 PCI 合规性,但 Mcafee 安全扫描抛出了一条:
通过非加密 (SSL) 通道发送的潜在敏感持久 Cookie
Drupal(默认行为)在以下情况下设置会话 cookie:您只需到达该站点即可。这是造成问题的原因。显然,整个网站不应该受 SSL 保护;许多其他网站都像这样设置会话 cookie。
什么给?
I am attempting to obtain PCI compliance for my site but the Mcafee security scan has thrown a:
Potential Sensitive Persistent Cookie Sent Over a Non-Encrypted (SSL) Channel
Drupal (default behavior) sets a session cookie when you simply arrive at the site. This is causing the problem. Clearly, the entire site shouldn't be under SSL; plenty of other sites set session cookies like this.
What gives?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
Drupal 什么版本?
您可能会考虑 Drupal 的 Pressflow 分支,它将一些修复从 Drupal 7 向后移植到早期版本。值得注意的一点是,它不会为匿名用户设置会话 cookie,除非他们确实需要。假设您不需要cookie,您也许可以避开整个问题。
What version of Drupal?
You might consider the Pressflow fork of Drupal, which backports some fixes from Drupal 7 to earlier versions. One of the notable ones is that it doesn't set a session cookie for anonymous users unless they actually need one. Assuming you don't need the cookies, you might be able to sidestep this whole problem.