<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Comparing QualysGuard PCI to Comodo HackerGuardian</title>
	<atom:link href="http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/</link>
	<description>Dave Koopman&#039;s Blog</description>
	<lastBuildDate>Wed, 08 Feb 2012 22:35:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Inner Game</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-61</link>
		<dc:creator>Inner Game</dc:creator>
		<pubDate>Fri, 08 Jan 2010 16:29:52 +0000</pubDate>
		<guid isPermaLink="false">#comment-61</guid>
		<description>Oh boy, I was just about to buy the Comodo product when I came across this post.

I just checked out the McAfee option, and of all the ones I checked out it seems to be the most professional one.

Nice write up, thank you.

S_</description>
		<content:encoded><![CDATA[<p>Oh boy, I was just about to buy the Comodo product when I came across this post.</p>
<p>I just checked out the McAfee option, and of all the ones I checked out it seems to be the most professional one.</p>
<p>Nice write up, thank you.</p>
<p>S_</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: erik</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-59</link>
		<dc:creator>erik</dc:creator>
		<pubDate>Fri, 27 Nov 2009 02:44:34 +0000</pubDate>
		<guid isPermaLink="false">#comment-59</guid>
		<description>directory listings that are intentional, isolated and are a part of functionality (like a documents directory or a source directory) should not make a site fail PCI.  Widespread unintentional listings should.  Please reread PCI</description>
		<content:encoded><![CDATA[<p>directory listings that are intentional, isolated and are a part of functionality (like a documents directory or a source directory) should not make a site fail PCI.  Widespread unintentional listings should.  Please reread PCI</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DaveK</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-20</link>
		<dc:creator>DaveK</dc:creator>
		<pubDate>Fri, 01 Aug 2008 00:01:38 +0000</pubDate>
		<guid isPermaLink="false">#comment-20</guid>
		<description>I&#039;ve received a call from Qualys, but missed the phone, they left me a message.  They caught wind of this blog article and wanted to tell me they did send me an email about the false positive analysis, and gave me the date/time they sent it.  I must have missed it, but going back through my email, I found this:

-------- Original Message --------
Subject: QualysGuard PCI Support -- False Positive Review
From: support at qualys.com
Date: Thu, March 27, 2008 9:21 am
To: [blurred]


User: David Koopman
Company: [blurred]
User Login: [blurred]

Qualys Support has reviewed your false positive request for scan ModPHP4 and
determined whether the identified issue(s) were accepted or rejected as false
positives.

If a false positive issue is accepted, then the vulnerability will no longer
show up in scan reports for the specific host. If a false positive issue is
rejected, then you must fix the vulnerability in order to meet PCI compliance
standards.

To view comments for accepted/rejected false positives, access the QualysGuard
PCI Web application using the following link:
https://pci.qualys.com/merchant/

For more information, please email Qualys Support:
mailto:support@qualys.com

(c) Copyright 2006-2007 Qualys, Inc. All rights reserved.
http://www.qualys.com
--------------------------------------

My account is no longer active, so I can&#039;t login to the PCI web application and view the reason.

I want to send my humble apology for claiming I didn&#039;t receive a response.  I just missed it.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve received a call from Qualys, but missed the phone, they left me a message.  They caught wind of this blog article and wanted to tell me they did send me an email about the false positive analysis, and gave me the date/time they sent it.  I must have missed it, but going back through my email, I found this:</p>
<p>&#8212;&#8212;&#8211; Original Message &#8212;&#8212;&#8211;<br />
Subject: QualysGuard PCI Support &#8212; False Positive Review<br />
From: support at qualys.com<br />
Date: Thu, March 27, 2008 9:21 am<br />
To: [blurred]</p>
<p>User: David Koopman<br />
Company: [blurred]<br />
User Login: [blurred]</p>
<p>Qualys Support has reviewed your false positive request for scan ModPHP4 and<br />
determined whether the identified issue(s) were accepted or rejected as false<br />
positives.</p>
<p>If a false positive issue is accepted, then the vulnerability will no longer<br />
show up in scan reports for the specific host. If a false positive issue is<br />
rejected, then you must fix the vulnerability in order to meet PCI compliance<br />
standards.</p>
<p>To view comments for accepted/rejected false positives, access the QualysGuard<br />
PCI Web application using the following link:<br />
<a href="https://pci.qualys.com/merchant/" rel="nofollow">https://pci.qualys.com/merchant/</a></p>
<p>For more information, please email Qualys Support:<br />
mailto:support@qualys.com</p>
<p>(c) Copyright 2006-2007 Qualys, Inc. All rights reserved.<br />
<a href="http://www.qualys.com" rel="nofollow">http://www.qualys.com</a><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>My account is no longer active, so I can&#8217;t login to the PCI web application and view the reason.</p>
<p>I want to send my humble apology for claiming I didn&#8217;t receive a response.  I just missed it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ravi</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-19</link>
		<dc:creator>Ravi</dc:creator>
		<pubDate>Wed, 30 Jul 2008 21:42:52 +0000</pubDate>
		<guid isPermaLink="false">#comment-19</guid>
		<description>Reading the PCI council guidelines, looks like false positives can&#039;t be removed from scanning altogether they need to be reviewed each time .. bummer!

PCI council wants to hear about bad scanning vendors ... they can be reported at https://www.pcisecuritystandards.org/docs/asv_feedback_form_-_client.doc</description>
		<content:encoded><![CDATA[<p>Reading the PCI council guidelines, looks like false positives can&#8217;t be removed from scanning altogether they need to be reviewed each time .. bummer!</p>
<p>PCI council wants to hear about bad scanning vendors &#8230; they can be reported at <a href="https://www.pcisecuritystandards.org/docs/asv_feedback_form_-_client.doc" rel="nofollow">https://www.pcisecuritystandards.org/docs/asv_feedback_form_-_client.doc</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ImGreen</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-18</link>
		<dc:creator>ImGreen</dc:creator>
		<pubDate>Fri, 18 Jul 2008 08:26:53 +0000</pubDate>
		<guid isPermaLink="false">#comment-18</guid>
		<description>I just ran a scan using Qualys QA and I got the same false positive. I guess this hasn&#039;t been fixed yet.</description>
		<content:encoded><![CDATA[<p>I just ran a scan using Qualys QA and I got the same false positive. I guess this hasn&#8217;t been fixed yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DaveK</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-14</link>
		<dc:creator>DaveK</dc:creator>
		<pubDate>Sun, 29 Jun 2008 17:30:28 +0000</pubDate>
		<guid isPermaLink="false">#comment-14</guid>
		<description>They never responded, but removed it as a vulnerability, so I guess they agreed.

Note: I have run a scan using McAfee Secure (previously HackerSafe).  I&#039;ll update this entry with those results when I get a chance.

7/31 AMENDMENT: see my 7/31 comment below, my 6/29 statement about never responding is incorrect.  I&#039;m only leaving this statement here for historical purpose.</description>
		<content:encoded><![CDATA[<p>They never responded, but removed it as a vulnerability, so I guess they agreed.</p>
<p>Note: I have run a scan using McAfee Secure (previously HackerSafe).  I&#8217;ll update this entry with those results when I get a chance.</p>
<p>7/31 AMENDMENT: see my 7/31 comment below, my 6/29 statement about never responding is incorrect.  I&#8217;m only leaving this statement here for historical purpose.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthew Kaufman</title>
		<link>http://www.koopman.me/2008/03/comparing-qualysguard-pci-to-comodo-hackerguardian/comment-page-1/#comment-13</link>
		<dc:creator>Matthew Kaufman</dc:creator>
		<pubDate>Tue, 17 Jun 2008 18:55:39 +0000</pubDate>
		<guid isPermaLink="false">#comment-13</guid>
		<description>Has Qualys replied to your report of the OpenSSH false positive yet? And if so, what did they say?</description>
		<content:encoded><![CDATA[<p>Has Qualys replied to your report of the OpenSSH false positive yet? And if so, what did they say?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

