Příspěvky

Zobrazují se příspěvky se štítkem PCI-DSS

MS Azure - AppService Configuration Vulnerability

Please note this critical vulnerability affects mainly those who use AppService for PCI DSS related services. As the service is not designed according to best security practices and security standards  ITS NOT COMPLIANT  with the PCI DSS standard at least its requirement 6. This in the end means the  complete customer service  is not compliant too. This is because the AppService is not designed and maintained according to best practices and industry standards as PCI DSS requires. I've started with development of some application with targeting the Azure as the hosting platform. Because I was ethical hacker for last 10 years I was interested how secure the Azure is before I'll put anything there. I've read all that stuff related to sandboxes and isolation level of VM's running in the cloud, especially those related to web applications... Its good to trust but also to check. Once I've created the account to the Azure Portal I have deployed my first small Asp...