<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PCI Compliance problems:    Same site scripting - due to &amp;quot;localhost.plus.com&amp;quot; in Broadband</title>
    <link>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880577#M349348</link>
    <description>&lt;P&gt;We've had to run "PCI compliance" scans for a number of years, to support taking credit card payments.&amp;nbsp; We're using Plusnet as the business broadband ISP and have a setup which is working well.&amp;nbsp; These scans have not been an issue for us, until recently.&amp;nbsp; I'm posting this here - to see if anyone else has encountered the same failure (also - as suggested by PN support).&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PCI scan report s&lt;SPAN&gt;tates that the issue is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;url: http://&lt;EM&gt;&lt;STRONG&gt;USERNAME&lt;/STRONG&gt;&lt;/EM&gt;.plus.com/&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;matched: Same site scripting detected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;Host: localhost.plus.com IP: 127.0.0.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This failure is raised when we scanned any other Plusnet internet connection IP address (e.g. those ending in *.plus.com).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what the PCI report says:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Threat&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Most of the DNS servers include records of the form localhost. IN A 127.0.0.1 But if by mistake, the administrator misses the trailing dot, the record is not fully qualified. So if the domain is example.com, the queries for localhost.example.com would resolve to 127.0.0.1. Reference: &lt;A href="https://seclists.org/bugtraq/2008/Jan/270" target="_blank"&gt;https://seclists.org/bugtraq/2008/Jan/270&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Impact:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The websites in affected domain cannot be securely accessed on multi-user system. The attacker can trick another user on the same system to access websites on affected domain in such a manner as to result in cross site scripting leaking cookies.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The websites in affected domain cannot be securely accessed on multi-user system. The attacker can trick another user on the same system to access websites on affected domain in such a manner as to result in cross site scripting leaking cookies.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Non fully qualified localhost entries should not be present in the nameserver for domains that host websites with HTTP state management (cookies).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's our DNS checks (using Google DNS) - we get the same with any DNS provider:&amp;nbsp; Plusnet resolves - but many other providers (e.g. bt.com) don't.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;nslookup&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; server 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Default Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; localhost.plus.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Non-authoritative answer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Name: localhost.plus.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 127.0.0.1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; localhost.bt.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - this isn't some "local" configuration issue and I've run out of ideas for how to resolve this.&amp;nbsp; As per the guidence - it seems there needs to be a change to make "plus.com" DNS entries behave correctly.&amp;nbsp; &amp;nbsp;Other major ISP's DNS do not resolve "localhost.isp.com", so why does PN ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had a Plusnet support case open for months - and been told today that &lt;EM&gt;"We don't know how to fix that"&lt;/EM&gt;.&amp;nbsp; When I asked if they could escolate it within the company we were told &lt;EM&gt;"I don't know who to escolate it to"&lt;/EM&gt;.&amp;nbsp; I was finally met with &lt;EM&gt;"We aren't responsible for PCI compliance, so we're not going to do anything".&lt;/EM&gt;&amp;nbsp; The support case handler - also said &lt;EM&gt;"We have't had any other reports of this - so we're not going to address it"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - I'm at a loss as to how to resolve this; with&amp;nbsp; no other answer, we'll have to move ISP.&amp;nbsp; Also - a little dissapointed in the least with the disregard given to potentional security issues in the PN platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any other ideas / observed the same sort if issue ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jul 2022 11:09:58 GMT</pubDate>
    <dc:creator>kquigley</dc:creator>
    <dc:date>2022-07-27T11:09:58Z</dc:date>
    <item>
      <title>PCI Compliance problems:    Same site scripting - due to "localhost.plus.com"</title>
      <link>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880577#M349348</link>
      <description>&lt;P&gt;We've had to run "PCI compliance" scans for a number of years, to support taking credit card payments.&amp;nbsp; We're using Plusnet as the business broadband ISP and have a setup which is working well.&amp;nbsp; These scans have not been an issue for us, until recently.&amp;nbsp; I'm posting this here - to see if anyone else has encountered the same failure (also - as suggested by PN support).&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PCI scan report s&lt;SPAN&gt;tates that the issue is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;url: http://&lt;EM&gt;&lt;STRONG&gt;USERNAME&lt;/STRONG&gt;&lt;/EM&gt;.plus.com/&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;matched: Same site scripting detected&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt;Host: localhost.plus.com IP: 127.0.0.1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This failure is raised when we scanned any other Plusnet internet connection IP address (e.g. those ending in *.plus.com).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's what the PCI report says:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Threat&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Most of the DNS servers include records of the form localhost. IN A 127.0.0.1 But if by mistake, the administrator misses the trailing dot, the record is not fully qualified. So if the domain is example.com, the queries for localhost.example.com would resolve to 127.0.0.1. Reference: &lt;A href="https://seclists.org/bugtraq/2008/Jan/270" target="_blank"&gt;https://seclists.org/bugtraq/2008/Jan/270&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Impact:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The websites in affected domain cannot be securely accessed on multi-user system. The attacker can trick another user on the same system to access websites on affected domain in such a manner as to result in cross site scripting leaking cookies.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The websites in affected domain cannot be securely accessed on multi-user system. The attacker can trick another user on the same system to access websites on affected domain in such a manner as to result in cross site scripting leaking cookies.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Non fully qualified localhost entries should not be present in the nameserver for domains that host websites with HTTP state management (cookies).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's our DNS checks (using Google DNS) - we get the same with any DNS provider:&amp;nbsp; Plusnet resolves - but many other providers (e.g. bt.com) don't.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;nslookup&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; server 8.8.8.8&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Default Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; localhost.plus.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Non-authoritative answer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Name: localhost.plus.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 127.0.0.1&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; localhost.bt.com&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Server: dns.google&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Address: 8.8.8.8&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - this isn't some "local" configuration issue and I've run out of ideas for how to resolve this.&amp;nbsp; As per the guidence - it seems there needs to be a change to make "plus.com" DNS entries behave correctly.&amp;nbsp; &amp;nbsp;Other major ISP's DNS do not resolve "localhost.isp.com", so why does PN ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've had a Plusnet support case open for months - and been told today that &lt;EM&gt;"We don't know how to fix that"&lt;/EM&gt;.&amp;nbsp; When I asked if they could escolate it within the company we were told &lt;EM&gt;"I don't know who to escolate it to"&lt;/EM&gt;.&amp;nbsp; I was finally met with &lt;EM&gt;"We aren't responsible for PCI compliance, so we're not going to do anything".&lt;/EM&gt;&amp;nbsp; The support case handler - also said &lt;EM&gt;"We have't had any other reports of this - so we're not going to address it"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So - I'm at a loss as to how to resolve this; with&amp;nbsp; no other answer, we'll have to move ISP.&amp;nbsp; Also - a little dissapointed in the least with the disregard given to potentional security issues in the PN platform.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have any other ideas / observed the same sort if issue ?&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 11:09:58 GMT</pubDate>
      <guid>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880577#M349348</guid>
      <dc:creator>kquigley</dc:creator>
      <dc:date>2022-07-27T11:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance problems:    Same site scripting - due to "localhost.plus.com"</title>
      <link>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880626#M349352</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/113634"&gt;@kquigley&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I was finally met with &lt;EM&gt;"We aren't responsible for PCI compliance, so we're not going to do anything".&lt;/EM&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If an ISP can't provide a PCI compliant connection then they can't really claim to be a business ISP.&lt;/P&gt;
&lt;P&gt;We take credit card payments, but we use Zettle (part of PayPal) who use a secure VPN system that means the connection is secure regardless of ISP (it actually connects via an Android or iOS0 app so works over WiFi or 4G). Other similar card processing companies are available.&lt;/P&gt;
&lt;P&gt;Alternatively, there are business oriented ISPs that do provide PCI compliant connections (we no longer use Plusnet so we've solved the problem both ways).&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 16:17:57 GMT</pubDate>
      <guid>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880626#M349352</guid>
      <dc:creator>corringham</dc:creator>
      <dc:date>2022-07-27T16:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Compliance problems:    Same site scripting - due to "localhost.plus.com"</title>
      <link>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880632#M349353</link>
      <description>&lt;P&gt;Some of these PCI scanning companies seem to be an ever evolving target. I know that's somewhat nature of the beast, however it doesn't explain why I've see scans fail in the past and then miraculously pass on subsequent attempts, despite targeting the exact same customer setup.&lt;/P&gt;
&lt;P&gt;Anyway, I digress. I can think of no useful reason why we're doing this, so I've logged it for somebody better versed than me to take a look (for my own benefit - ref: IS-3843).&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 16:48:39 GMT</pubDate>
      <guid>https://community.plus.net/t5/Broadband/PCI-Compliance-problems-Same-site-scripting-due-to-quot/m-p/1880632#M349353</guid>
      <dc:creator>bobpullen</dc:creator>
      <dc:date>2022-07-27T16:48:39Z</dc:date>
    </item>
  </channel>
</rss>

