block ports 21 and 2077 on server for PCI compliance

En curso Publicado Nov 6, 2013 Pagado a la entrega
En curso Pagado a la entrega

I have a server trying to meet PCI compliance and the scan from Trustwave has highlighted the details below regarding port 21 and port 2077.

Tech support for my server says these can be blocked but they don't offer a service for doing the actual work. They say it can be done using IP tables as it is a dedicated server.

So as far as I understand, I need to get these ports blocked and am looking for someone with the skills and knowledge to do this.

Unencrypted Communication Channel Accessibility

port 21

The service running on this port (most often Telnet, FTP, etc…) appears to make use of a plaintext (unencrypted) communication channel. Payment industry policies (PCI 1.1.5.b, 2.2.2.b, 2.3, & 8.4.a) forbid the use of such insecure services/protocols. Unencrypted communication channels are vulnerable to the disclosure and/or modification of any data transiting through them (including usernames and passwords), and as such the confidentially and integrity of the data in transit cannot be ensured with any level of certainty.

Web Application Transmits Login Credentials Without Encryption

port 2077

There is a web application running on this host that transmits login credentials over HTTP, which is a cleartext protocol. As such, if an attacker was able to intercept traffic containing login credentials, it would be trivial to view user account and password information."

Administración de sistemas Web Hosting Seguridad web Gestión de páginas web

Nº del proyecto: #5100142

Sobre el proyecto

6 propuestas Proyecto remoto Activo Nov 6, 2013

6 freelancers están ofertando un promedio de £64 por este trabajo

drailean

A proposal has not yet been provided

£88 GBP en 1 día
(53 comentarios)
5.4
muzzamilnoor

Expert Info security expert and system administrator here. We need to first find out why these ports are open and then can easily be closed.

£20 GBP en 1 día
(20 comentarios)
5.4
s2fdsindia

Hi , We are linux professionals holding experience in hosting environments. We have experience in doing this for PCI compliance. We can do this for you.

£20 GBP en 0 días
(42 comentarios)
4.5
ggabor67

Hi nrg3g, I'm system administrator since 1996. I'm sure, I can fix your problem. Just call me. Regards, George

£50 GBP en 0 días
(0 comentarios)
0.0
romeroc24

La propuesta todavía no ha sido proveída

£150 GBP en 3 días
(0 comentarios)
0.0