<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8617772315054487261</id><updated>2011-09-04T08:55:25.671-07:00</updated><category term='applications'/><category term='latest certified'/><category term='OWASP'/><category term='ipad'/><category term='link'/><category term='pin'/><category term='critics'/><category term='atm'/><category term='atm rootkit'/><category term='hacking'/><category term='PCI DSS'/><category term='conference'/><category term='complying%20with%20PA-DSS'/><category term='pa-dss'/><category term='application security'/><category term='open-source'/><category term='presentation'/><title type='text'>PA-DSS: Payment Application Data Security Standart</title><subtitle type='html'>Blog about payment application security and compliance by Alexander Polyakov (dsecrg.com)</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>18</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-8307294610281900521</id><published>2010-05-21T12:56:00.000-07:00</published><updated>2010-05-21T13:08:33.093-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='link'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>New articles about PA-DSS</title><content type='html'>This week gives us 2 interesting articles about PA-DSS&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://nichecashworld.com/5189/pci-compliancy-and-the-pa-dss-protects-those-involved-in-e-commerce/"&gt;PCI Compliancy And The PA-DSS Protects Those Involved In E-Commerce&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2. &lt;a href="http://www.spiguard.com/blog/pa-dss-things-to-remember/"&gt;PA-DSS – Things to remember&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-8307294610281900521?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/8307294610281900521/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/new-articles-about-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/8307294610281900521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/8307294610281900521'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/new-articles-about-pa-dss.html' title='New articles about PA-DSS'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4758864077614729412</id><published>2010-05-11T12:21:00.000-07:00</published><updated>2010-05-21T12:50:17.300-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='latest certified'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>latest certified PA-DSS applications. 11 may 2010</title><content type='html'>by the 11 th of may we have 7 new certified applications from 6 vendors:&lt;br /&gt;4 of them are completely new and 3 are re qualified versions of old applications.&lt;br /&gt;5 of them are POS applications and 1-Payment Gateway 1-Payment Midleware.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. &lt;span style="font-weight:bold;"&gt;(NEW)&lt;/span&gt;AccuPOS 10  by &lt;a href="www.attitudepositive.com"&gt;Attitude Positive &lt;/a&gt; &lt;br /&gt;2. &lt;span style="font-weight:bold;"&gt;(NEW)&lt;/span&gt;AccuPOS 11  by &lt;a href="www.attitudepositive.com"&gt;Attitude Positive &lt;/a&gt; &lt;br /&gt;3. &lt;span style="font-weight:bold;"&gt;(NEW)&lt;/span&gt;Star~Lite   by &lt;a href="www.auto-star.com"&gt;Auto~Star Compusystems, Inc.&lt;/a&gt;&lt;br /&gt;4. &lt;span style="font-weight:bold;"&gt;(REQUALIFICATION)&lt;/span&gt;ICON 9.0X   by &lt;a href="www.Civica.co.uk"&gt;Civica&lt;/a&gt;&lt;br /&gt;5. &lt;span style="font-weight:bold;"&gt;(REQUALIFICATION)&lt;/span&gt; ChargeItPro 3.03 by &lt;a href="www.chargeitpro.com"&gt;Payment Processing Partners, Inc.&lt;/a&gt;&lt;br /&gt;6. &lt;span style="font-weight:bold;"&gt;(NEW)&lt;/span&gt;ProfitMaster Payment Interface (PPI) by &lt;a href="pmcanada.com"&gt;ProfitMaster Canada&lt;/a&gt;&lt;br /&gt;7. &lt;span style="font-weight:bold;"&gt;(REQUALIFICATION)&lt;/span&gt; InFusion 3.50 SP3&lt;br /&gt; by &lt;a href="www.partech.com"&gt;Partech&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;all information was taken from &lt;a href="https://www.pcisecuritystandards.org/security_standards/vpa/vpa_approval_list.html"&gt;official site&lt;/a&gt; of PCI Council by the 11th may of 2010&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4758864077614729412?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4758864077614729412/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/latest-certified-pa-dss-applications-11.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4758864077614729412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4758864077614729412'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/latest-certified-pa-dss-applications-11.html' title='latest certified PA-DSS applications. 11 may 2010'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4206042500478206533</id><published>2010-05-11T07:00:00.000-07:00</published><updated>2010-05-11T07:10:45.696-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='application security'/><category scheme='http://www.blogger.com/atom/ns#' term='atm rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='atm'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Prepare to "Jackpotting Automated Teller Machines Redux"</title><content type='html'>In near &lt;a href="http://blackhat.com/html/bh-us-10/bh-us-10-briefings.html"&gt;BlackHat event 2010&lt;/a&gt; in Las Vegas &lt;a href="http://blackhat.com/html/bh-us-10/bh-us-10-speaker_bios.html#Jack"&gt;Barnaby Jack&lt;/a&gt; will show us a presentation about remotely and locally attacking ATM's and also an example of ATM rootkit. I hope it will be wery interesting because Jack's presentation in 2009 &lt;a href="http://www.wired.com/threatlevel/2009/06/atm-vendor-halts-talk/"&gt;was halted&lt;/a&gt; by ATM Vendor because those vulnerabilities was 0-days and very critical.  So get ready !&lt;br /&gt;&lt;br /&gt;Here is some text from announcement:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"Jackpotting Automated Teller Machines Redux"&lt;span style="font-weight:bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;The presentation "Jackpotting Automated Teller Machines" was originally on the schedule at Black Hat USA 2009. Due to circumstances beyond my control, the talk was pulled at the last minute. The upside to this is that there has been an additional year to research ATM attacks, and I'm armed with a whole new bag of tricks.&lt;br /&gt;&lt;br /&gt;I've always liked the scene in Terminator 2 where John Connor walks up to an ATM, interfaces his Atari to the care presentation "Jackpotting Automated Teller Machines" was originally on the schedule at Black Hat USA 2009. Due to circumstances beyond my control, the talk was pulled at the last minute. The upside to this is that there has been an additional year to research ATM attacks, and I'm armed with a whole new bag of tricks.&lt;br /&gt;&lt;br /&gt;I've always liked the scene in Terminator 2 where John Connor walks up to an ATM, interfaces his Atari to the card reader and retrieves cash from the machine. I think I've got that kid beat.&lt;br /&gt;&lt;br /&gt;The most prevalent attacks on Automated Teller Machines typically involve the use of card skimmers, or the physical theft of the machines themselves. Rarely do we see any targeted attacks on the underlying software.&lt;br /&gt;&lt;br /&gt;Last year, there was one ATM; this year, I'm doubling down and bringing two new model ATMs from two major vendors. I will demonstrate both local and remote attacks, and I will reveal a multi-platform ATM rootkit. Finally, I will discuss protection mechanisms that ATM manufacturers can implement to safeguard against these attacks.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4206042500478206533?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4206042500478206533/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/prepare-to-jackpotting-automated-teller.html#comment-form' title='Комментарии: 1'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4206042500478206533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4206042500478206533'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/prepare-to-jackpotting-automated-teller.html' title='Prepare to &quot;Jackpotting Automated Teller Machines Redux&quot;'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4168476899738758289</id><published>2010-05-11T06:34:00.000-07:00</published><updated>2010-05-11T06:39:22.492-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='link'/><category scheme='http://www.blogger.com/atom/ns#' term='applications'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>Passport® with PA-DSS Point of Sale System is using by Heartland,  RBS WorldPay and many others</title><content type='html'>&lt;a href="http://www.gilbarco.com/object/PR05May2010.html"&gt;More Networks Certify Passport® with PA-DSS Point of Sale System&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;"GREENSBORO, N.C. – May 5, 2010 – Heartland Payment Systems (Dallas) for CITGO, Marathon and unbranded customers, along with RBS WorldPay, have approved Passport with PA-DSS point of sale system software for retailers on their networks. They join BP, Chevron, Concord (Gulf, Sinclair, Sunoco, Valero and unbranded), ExxonMobil, NBS/Cenex, and Shell software applications that are already shipping."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Passport has the most networks approved with a PA-DSS validated application for convenience store operators.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4168476899738758289?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4168476899738758289/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/passport-with-pa-dss-point-of-sale.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4168476899738758289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4168476899738758289'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/passport-with-pa-dss-point-of-sale.html' title='Passport® with PA-DSS Point of Sale System is using by Heartland,  RBS WorldPay and many others'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-2766778008863740807</id><published>2010-05-04T12:02:00.000-07:00</published><updated>2010-05-04T12:05:39.065-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='open-source'/><category scheme='http://www.blogger.com/atom/ns#' term='link'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>PA-DSS and opensource part 2</title><content type='html'>another one &lt;a href="http://slashdot.org/submission/1227990/PA-DSS-and-Opensource-Applications?from=rss&amp;utm_source=twitterfeed&amp;utm_medium=twitter"&gt;article &lt;/a&gt;about opensource PA-DSS applications&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-2766778008863740807?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/2766778008863740807/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/pa-dss-and-opensource-part-2.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/2766778008863740807'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/2766778008863740807'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/pa-dss-and-opensource-part-2.html' title='PA-DSS and opensource part 2'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-3466596834832410028</id><published>2010-05-03T12:00:00.000-07:00</published><updated>2010-05-21T12:20:28.042-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='latest certified'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>latest certified PA-DSS applications. 3 may 2010</title><content type='html'>by the 3rd of may there are 7 new certified applications:&lt;br /&gt;&lt;br /&gt;1. ActiveRetail Enterprise by &lt;a href="www.argility.com  "&gt;Argility &lt;/a&gt; &lt;br /&gt;&lt;br /&gt;2. IVR for Payment Gateway (IVRFPG) by &lt;a href="www.baytalkitec.com  "&gt;Bay Talkitec&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. CAGE by &lt;a href="www.innovative-control.com  "&gt;Innovative Control Systems&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. OPERA Enterprise Solution by &lt;a href="www.micros.com  "&gt;Mircos&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;5. X-Series TMS by &lt;a href="www.panasonic.aero  "&gt;Panasonic&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;6. VersaPOS by &lt;a href="www.systime.net  "&gt;Systime Computer Systems&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;7. VenuemasterВІ by &lt;a href="www.ticketmaster.co.uk  "&gt;Ticketmaster UK&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;all information was taken from &lt;a href="https://www.pcisecuritystandards.org/security_standards/vpa/vpa_approval_list.html"&gt;official site&lt;/a&gt; of PCI Council&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-3466596834832410028?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/3466596834832410028/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/05/latest-certified-pa-dss-applications-3.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/3466596834832410028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/3466596834832410028'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/05/latest-certified-pa-dss-applications-3.html' title='latest certified PA-DSS applications. 3 may 2010'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-2198527014416569044</id><published>2010-04-26T14:58:00.000-07:00</published><updated>2010-04-26T15:12:14.482-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conference'/><category scheme='http://www.blogger.com/atom/ns#' term='application security'/><category scheme='http://www.blogger.com/atom/ns#' term='presentation'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>Application Security and pa-dss certification</title><content type='html'>I've posted my &lt;a href="http://www.slideshare.net/alexandrpolyakov/application-security-and-pa-dss-certification"&gt;presentation&lt;/a&gt; from &lt;a href="http://www.cardexpo.ru/ru/conference/program/"&gt;cardexpo&lt;/a&gt;. Firstly it is about importance of application security in a PCI Security area and of cause about a PA-DSS standard and advantages for application vendors and merchants for getting &lt;a href="http://dsecrg.com/pages/services/pa-dss/"&gt;PA-DSS compliance&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_3862761"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/alexandrpolyakov/application-security-and-pa-dss-certification" title="Application security and pa dss certification"&gt;Application security and pa dss certification&lt;/a&gt;&lt;/strong&gt;&lt;object width="425" height="338"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=applicationsecurityandpa-dsscertification-100426165505-phpapp02&amp;stripped_title=application-security-and-pa-dss-certification" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=applicationsecurityandpa-dsscertification-100426165505-phpapp02&amp;stripped_title=application-security-and-pa-dss-certification" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="338"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/alexandrpolyakov"&gt;Alexander Polyakov&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-2198527014416569044?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/2198527014416569044/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/application-security-and-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/2198527014416569044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/2198527014416569044'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/application-security-and-pa-dss.html' title='Application Security and pa-dss certification'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-6616255618198646239</id><published>2010-04-23T09:11:00.000-07:00</published><updated>2010-04-23T09:20:28.193-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pin'/><category scheme='http://www.blogger.com/atom/ns#' term='atm'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Hacking ATM</title><content type='html'>really good &lt;a href="http://conference.hitb.org/hitbsecconf2010dxb/materials/D1%20-%20Dimitri%20Petropoulos%20-%20Attacking%20ATMs%20&amp;%20HSMs.pdf"&gt;presentation&lt;/a&gt; by Dimitris Petropoulos about ATM and HSM hacking which combines all known and new  attacks on PIN algoritms. Must see for everyone who is interested in PIN (IN)security :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-6616255618198646239?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/6616255618198646239/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/hacking-atm.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/6616255618198646239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/6616255618198646239'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/hacking-atm.html' title='Hacking ATM'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-5390020825828484885</id><published>2010-04-22T14:26:00.000-07:00</published><updated>2010-04-22T14:39:27.107-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='application security'/><category scheme='http://www.blogger.com/atom/ns#' term='complying%20with%20PA-DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>NEW TOPIC: "Complying with PA-DSS" Requirement 5.2.1 (Practical guide to fix XSS vulnerabilitiess)</title><content type='html'>I topic "Complying with PA-DSS" i will show a different ways which will help you to comply with different Requirements.&lt;br /&gt;So as we start to talk about web application security in previous &lt;a href="http://pa-dss.blogspot.com/2010/04/importance-of-web-application-security.html"&gt;topic&lt;/a&gt; lets continue in this area. The most popular web application vulnerability is XSS as u mentioned &lt;a href="http://www.whitehatsec.com/home/assets/WPstats_fall09_8th.pdf"&gt;earlier&lt;/a&gt; so here is the &lt;a href="http://amrita.edu/cyber-workshop/proceedings/icscf09_submission_49.pdf"&gt;guide &lt;/a&gt;for developers how to fix XS vulnerabilities and write secure code.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-5390020825828484885?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/5390020825828484885/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/new-topic-complying-with-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/5390020825828484885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/5390020825828484885'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/new-topic-complying-with-pa-dss.html' title='NEW TOPIC: &quot;Complying with PA-DSS&quot; Requirement 5.2.1 (Practical guide to fix XSS vulnerabilitiess)'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-3290381904931156880</id><published>2010-04-22T14:04:00.000-07:00</published><updated>2010-04-22T14:16:04.695-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='application security'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>Importance of web application security in PA-DSS certification</title><content type='html'>WhiteHat Security published &lt;a href="http://www.whitehatsec.com/home/assets/WPstats_fall09_8th.pdf"&gt;report&lt;/a&gt; with different statistics about web application vulnerabilities which shows the importance of web application security assessment which is needed in Requirement 6.5 of PCI DSS and 5.2 of PA-DSS.&lt;br /&gt;More on importance of application security in PA-DSS assessment in presentation from &lt;a href="http://pcidss.ru/blog/53.html"&gt;Cardexpo&lt;/a&gt; which will be available soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-3290381904931156880?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/3290381904931156880/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/importance-of-web-application-security.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/3290381904931156880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/3290381904931156880'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/importance-of-web-application-security.html' title='Importance of web application security in PA-DSS certification'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4833245355201665164</id><published>2010-04-20T13:45:00.000-07:00</published><updated>2010-04-20T13:49:55.160-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='application security'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>OWASP Top 10 Final version Released</title><content type='html'>On April 19, 2010 &lt;a href="http://www.owasp.org"&gt;OWASP &lt;/a&gt;released the final version of the OWASP Top 10 for 2010, and here is the associated &lt;a href="http://www.owasp.org/index.php/OWASPTop10-2010-PressRelease"&gt;press release&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;The OWASP Top 10 Web Application Security Risks for 2010 are: &lt;br /&gt;&lt;br /&gt;A1: Injection &lt;br /&gt;A2: Cross-Site Scripting (XSS) &lt;br /&gt;A3: Broken Authentication and Session Management &lt;br /&gt;A4: Insecure Direct Object References &lt;br /&gt;A5: Cross-Site Request Forgery (CSRF) &lt;br /&gt;A6: Security Misconfiguration &lt;br /&gt;A7: Insecure Cryptographic Storage &lt;br /&gt;A8: Failure to Restrict URL Access &lt;br /&gt;A9: Insufficient Transport Layer Protection &lt;br /&gt;A10: Unvalidated Redirects and Forwards&lt;br /&gt;&lt;br /&gt;Now u must use those risks in PCI DSS and PA-DSS compliance assessments .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4833245355201665164?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4833245355201665164/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/owasp-top-10-final-version-released.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4833245355201665164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4833245355201665164'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/owasp-top-10-final-version-released.html' title='OWASP Top 10 Final version Released'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4270408892101198832</id><published>2010-04-19T08:21:00.000-07:00</published><updated>2010-04-19T08:37:14.646-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='latest certified'/><category scheme='http://www.blogger.com/atom/ns#' term='applications'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>New topic: latest certified PA DSS applications</title><content type='html'>From this day i will post here the latest PA-DSS certified applications:&lt;br /&gt;&lt;br /&gt;This week we have 2 press releases:&lt;br /&gt;&lt;br /&gt;1. 17 april 2010: &lt;a href="http://www.pr.com/press-release/227698"&gt;SalePoint Announces PA-DSS Validation of Trovato Point of Sale Software&lt;/a&gt;&lt;br /&gt;2. 13 april 2010 &lt;a href="http://www.tradingmarkets.com/news/stock-alert/hyc_hypercom-payment-software-earns-pci-pa-dss-security-validation-909764.html"&gt;Hypercom Payment Software Earns PCI PA-DSS Security Validation&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4270408892101198832?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4270408892101198832/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/new-topic-latest-certified-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4270408892101198832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4270408892101198832'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/new-topic-latest-certified-pa-dss.html' title='New topic: latest certified PA DSS applications'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-1239988956147708468</id><published>2010-04-19T07:09:00.000-07:00</published><updated>2010-04-19T08:38:02.913-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='open-source'/><category scheme='http://www.blogger.com/atom/ns#' term='link'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>PA DSS and open source applications</title><content type='html'>Really good &lt;a href="http://pciguru.wordpress.com/2010/04/10/open-source-pa-dss-certification/"&gt;article&lt;/a&gt; about problems of certificating open-source applications.&lt;br /&gt;&lt;br /&gt;As i see (And my point of view is the same like in article), the most problems lay on the process of development. Those things like SLDC, secure updates, change control and documentation of process is really hard to implement when u talk about open-source software. And of-cause there if a problem with payment for certification,i don't think that developers can pay 30k$ or about for certification precess )&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-1239988956147708468?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/1239988956147708468/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/pa-dss-and-open-source-applications.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/1239988956147708468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/1239988956147708468'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/pa-dss-and-open-source-applications.html' title='PA DSS and open source applications'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4272905499044984997</id><published>2010-04-16T14:38:00.000-07:00</published><updated>2010-04-16T14:40:33.966-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conference'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>Developers Guide to PCI DSS and PA-DSS Requirements</title><content type='html'>While searching information for my feature talk about Application Security and PA-DSS Complience in &lt;a href="http://www.cardexpo.ru/"&gt;CardExpo&lt;/a&gt; Conference which will be held in Moscow (Rusiia) 20 april I found a good &lt;a href="http://vimeo.com/6495344"&gt;video&lt;/a&gt; for developers about PCI and PA DSS Compliance from OWASP MSP 2009 by Sets Peter.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4272905499044984997?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4272905499044984997/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/developers-guide-to-pci-dss-and-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4272905499044984997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4272905499044984997'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/developers-guide-to-pci-dss-and-pa-dss.html' title='Developers Guide to PCI DSS and PA-DSS Requirements'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-7072088111681085938</id><published>2010-04-13T14:06:00.000-07:00</published><updated>2010-04-13T14:10:31.130-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='link'/><category scheme='http://www.blogger.com/atom/ns#' term='atm'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>ATM's and PA-DSS</title><content type='html'>ATMs: PTS, PCI DSS, or PA-DSS?  In 2 worlds the answer is:&lt;br /&gt;&lt;br /&gt;PTS applies to the PIN pad component of ATM&lt;br /&gt;PA-DSS applies to the software running on ATM (potentially)&lt;br /&gt;PCI DSS applies to the company that drives the ATM network&lt;br /&gt;&lt;br /&gt;more information here &lt;a href="http://chaordicmind.com/blog/2009/11/08/atms-pts-pci-dss-or-pa-dss/"&gt;ATMs: PTS, PCI DSS, or PA-DSS? by Michael Dahn&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-7072088111681085938?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/7072088111681085938/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/atms-and-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/7072088111681085938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/7072088111681085938'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/atms-and-pa-dss.html' title='ATM&apos;s and PA-DSS'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-4525554638169311375</id><published>2010-04-12T15:20:00.000-07:00</published><updated>2010-04-19T08:38:45.152-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='critics'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><category scheme='http://www.blogger.com/atom/ns#' term='ipad'/><title type='text'>ipad and PA-DSS</title><content type='html'>interesting article about Ipad Applications and PA-DSS &lt;a href="http://blogs.csoonline.com/1190/stop_the_madness_payment_apps_are_on_the_ipad_too_soon"&gt; link&lt;/a&gt;. BTW the first (if believe to authors) PA DSS compliant application is available in &lt;a href="http://itunes.apple.com/us/app/swipe-credit-card-terminal/id309329440?mt=8"&gt;istore&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;P.S. I take a look at &lt;a href="https://www.pcisecuritystandards.org/security_standards/vpa/vpa_approval_list.html?mn=&amp;vn=435&amp;an=0&amp;ap=0&amp;sortfield=0&amp;sortdir=0"&gt;List of Validated Payment Applications&lt;/a&gt; and did not find anything about this application. So u must be aware of such types of applications :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-4525554638169311375?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/4525554638169311375/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/ipad-and-pa-dss.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4525554638169311375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/4525554638169311375'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/ipad-and-pa-dss.html' title='ipad and PA-DSS'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-5262234302800403040</id><published>2010-04-07T02:14:00.000-07:00</published><updated>2010-04-19T08:39:13.397-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conference'/><category scheme='http://www.blogger.com/atom/ns#' term='presentation'/><category scheme='http://www.blogger.com/atom/ns#' term='pa-dss'/><title type='text'>pcidssrussia 2010</title><content type='html'>In 17th march i make a talk in &lt;a href="http://pcidssrussia.com"&gt;pcidssrussia2010&lt;/a&gt; conference which was wery great event btw. I have 2 talks in this conference. One was about technical aspects of PCI DS Compliance where the main idea was "Thinking about purpose of requirement may help u to save time, money and make good solution which will be Secure and Compliant"&lt;br /&gt;&lt;br /&gt;Another talk was about introduction to PA-DSS for beginners. Nothing special but good starting point.&lt;br /&gt;&lt;br /&gt;download presentation (&lt;a href="http://pcidssrussia.ru/files/The%20main%20features%20of%20PA-QSA%20certification.pdf"&gt;In Russian&lt;/a&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-5262234302800403040?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/5262234302800403040/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/pcidssrussia-2010.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/5262234302800403040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/5262234302800403040'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/pcidssrussia-2010.html' title='pcidssrussia 2010'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8617772315054487261.post-258277858450412846</id><published>2010-04-07T01:54:00.001-07:00</published><updated>2010-04-07T02:09:06.882-07:00</updated><title type='text'>beginning</title><content type='html'>&lt;p&gt;Hello my name is Alexander Polyakov. I work in a &lt;a href="http://dsec.ru"&gt;Digital Security&lt;/a&gt; Company as a lead of it security audit department and I also a head of our research group &lt;a href="http://dsecrg.com"&gt;DSecRG&lt;/a&gt; which focused in finding vulnerabilities and research in enterprise application security area.&lt;br /&gt;&lt;br /&gt;As I am also PCA QSA and PA QSA I decide to start new project in payment application security area and write here my research and thoughts about this. So ewerybody wellcome!&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8617772315054487261-258277858450412846?l=pa-dss.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pa-dss.blogspot.com/feeds/258277858450412846/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://pa-dss.blogspot.com/2010/04/beginning_07.html#comment-form' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/258277858450412846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8617772315054487261/posts/default/258277858450412846'/><link rel='alternate' type='text/html' href='http://pa-dss.blogspot.com/2010/04/beginning_07.html' title='beginning'/><author><name>Alexander Polyakov</name><uri>http://www.blogger.com/profile/15703333293651201324</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
