Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: IIS log

From: Richard M. Smith <rms(at)computerbytesman.com>
Date: Tue Aug 05 2003 - 16:07:38 EDT


If someone is using the GET method in a form that accepts credit card numbers, then the numbers will end up in a log file. Forms that accept personal information should always use the POST method.

Richard

-----Original Message-----

From: Michael Howard [mailto:mikehow@microsoft.com] Sent: Tuesday, August 05, 2003 3:58 PM
To: Justin H Tran; webappsec@securityfocus.com Subject: RE: IIS log

Iis doesn't log credit card numbers!!! There's no concept of CCs in HTTP!!! My guess, and it is a guess, is some other app running on top of iis is logging the data, or the data is in the URI

Can you send me a snippet of the log?replace the CC# with something bopgus

-----Original Message-----

From: Justin H Tran [mailto:justint@us.ibm.com] Sent: Tuesday, August 05, 2003 12:35 PM
To: webappsec@securityfocus.com
Subject: IIS log

I just viewed an IIS log and I noticed that the credit card # is loogged.
I beleive that this is a major flaw to log credit card # is clear text. Does anyone have any advice?

Regards,
Justin Received on Tue Aug 5 18:24:40 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:54 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library