<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data In Motion - a Managed File Transfer blog &#187; Host Access</title>
	<atom:link href="http://www.attachmate.com/blogs/datainmotion/index.php/tag/host-access/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.attachmate.com/blogs/datainmotion</link>
	<description> The Attachmate blog on data security and managed file transfer</description>
	<lastBuildDate>Tue, 06 Aug 2013 15:59:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Safely Accessing Host Data from the Web</title>
		<link>http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/</link>
		<comments>http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/#comments</comments>
		<pubDate>Tue, 06 Sep 2011 20:33:38 +0000</pubDate>
		<dc:creator>Sam Morris</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Host Access]]></category>
		<category><![CDATA[Legacy]]></category>
		<category><![CDATA[PCI-DSS]]></category>

		<guid isPermaLink="false">http://www.attachmate.com/blogs/datainmotion/?p=329</guid>
		<description><![CDATA[<p>Maintaining PCI-DSS Compliance While Accessing Host Data via the Web Everyone has a web browser. That means you can make data available to everyone who needs it by putting it on the web. Even data accessed through legacy host applications can be made available on the web – without touching the mainframe or the host application. Simply by [...]<p><a href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/">Safely Accessing Host Data from the Web</a> is a post from: <a href="http://www.attachmate.com/blogs/datainmotion">Data In Motion - a Managed File Transfer blog</a></p>
</p><p>The post <a href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/">Safely Accessing Host Data from the Web</a> appeared first on <a href="http://www.attachmate.com/blogs/datainmotion">Data In Motion - a Managed File Transfer blog</a>.</p>]]></description>
			<content:encoded><![CDATA[<h3>Share and Enjoy</h3>
<div class="wp-socializer-buttons clearfix">
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Facebook Button -->
<div class="fb-like" data-href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-send="false" data-layout="box_count" data-width="55" data-show-faces="0" data-action="like" data-font="arial" data-colorscheme="light"></div>
<!-- End WP Socializer Plugin - Facebook Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Retweet Button -->
<a href="http://twitter.com/share" class="twitter-share-button" data-count="vertical"  data-lang="en"  data-url="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-text="Safely Accessing Host Data from the Web - "></a>
<!-- End WP Socializer Plugin - Retweet Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - +1 Button -->
<g:plusone size="tall" href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" ></g:plusone>
<!-- End WP Socializer Plugin - +1 Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - StumbleUpon Button -->
<su:badge layout="5"></su:badge>
<!-- End WP Socializer Plugin - StumbleUpon Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Reddit Button -->
<script type="text/javascript">reddit_url = "http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/";reddit_title = "Safely Accessing Host Data from the Web";reddit_newwindow="1";</script><script type="text/javascript" src="http://www.reddit.com/static/button/button2.js"></script>
<!-- End WP Socializer Plugin - Reddit Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - LinkedIn Button -->
<script type="IN/Share" data-url="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-counter="top"></script>
<!-- End WP Socializer Plugin - LinkedIn Button -->
</span>
<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Pinterest Button -->
<a href="http://pinterest.com/pin/create/button/?url=http%3A%2F%2Fwww.attachmate.com%2Fblogs%2Fdatainmotion%2Findex.php%2Fsafely-accessing-host-data-from-the-web%2F&amp;media=http%3A%2F%2Fwww.attachmate.com%2Fblogs%2Fdatainmotion%2Fwp-content%2Fuploads%2F2011%2F09%2FXSS.jpg" class="pin-it-button" count-layout="vertical"><img border="0" src="//assets.pinterest.com/images/PinExt.png" alt="Pinterest" title="Pin It" /></a>
<!-- End WP Socializer Plugin - Pinterest Button -->
</span>
</div><p></p><p>Maintaining PCI-DSS Compliance While Accessing Host Data via the Web</p>
<p>Everyone has a web browser.</p>
<p>That means you can make data available to everyone who needs it by putting it on the web. Even data accessed through legacy host applications can be made available on the web – without touching the mainframe or the host application. Simply by using a web-based terminal emulation or file transfer program, users with nothing more than a web browser can access everything they need.</p>
<p>That part is easy. The hard part is security.  If your organization deals with credit cards, you need to comply with PCI-DSS (Payment Card Industry – Data Security Standards), which means you have to defend against cross-site scripting (XSS) attacks.<span id="more-329"></span></p>
<p>Cross-site scripting? XSS? What&#8217;s that about? When you authenticate to a website, the web server returns a &#8220;session cookie&#8221; to your browser. When you click on other pages, your browser sends that session cookie back to the server, to say &#8220;hey, it&#8217;s me again, the person you just authenticated.&#8221;<a href="http://www.attachmate.com/blogs/datainmotion/wp-content/uploads/2011/09/XSS.jpg"><img class="alignright size-full wp-image-333" title="XSS" src="http://www.attachmate.com/blogs/datainmotion/wp-content/uploads/2011/09/XSS.jpg" alt="Defend against Cross-site Scripting (XSS) for PCI compliance" width="217" height="157" /></a></p>
<p>The session cookie is a big convenience – it means you don’t have to enter your password repeatedly. But it has to be kept secure. If someone steals your session cookie, they might be able to use it to impersonate you and steal your data.</p>
<p>That&#8217;s where XSS attacks come in. Some websites have coding flaws that allow attackers to plant malicious scripts that run when you connect to the site. The scripts ask your browser to read your session cookie and send it back to the attacker, who can then try to hijack your session.</p>
<p>Fixing those coding flaws is the best answer, but that&#8217;s hard to get right. So a powerful fall-back defense was developed: the &#8220;HTTPOnly&#8221; flag.</p>
<p>HTTPOnly is a simple idea. The web server marks the session cookie as HTTPOnly. That tells the browser, &#8220;don&#8217;t let scripts read this cookie – only proper HTTP requests are allowed to use it.&#8221; So if a malicious script asks the browser to read the cookie, the browser will refuse.</p>
<p>It&#8217;s a powerful defense, which is why PCI-DSS requires use of HTTPOnly.</p>
<p>You might be wondering why the browser needs to be told not to read the cookie on behalf of a script. The answer lies in some unfortunate history. In the early days of the web, poorly behaved applications commonly manipulated the cookie directly.  Modern applications, if they are designed for security, leave it to the browser to handle the cookie, and do not try to read it directly.</p>
<p>One hallmark of a well-designed, secure web application is that it functions correctly even if HTTPOnly has been enabled on the web server. If an application malfunctions when HTTPOnly is turned on, that’s a sure sign that the application is not well-behaved when it comes to cookies and security.</p>
<p>The takeaway: to comply with PCI-DSS, you need to enable HTTPOnly. If this causes problems for your application, then you need to question your vendor about whether the application is properly designed.</p>
<p><a href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/">Safely Accessing Host Data from the Web</a> is a post from: <a href="http://www.attachmate.com/blogs/datainmotion">Data In Motion - a Managed File Transfer blog</a></p>
<h3>Share and Enjoy</h3>
<div class="wp-socializer-buttons clearfix">
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Facebook Button -->
<div class="fb-like" data-href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-send="false" data-layout="box_count" data-width="55" data-show-faces="0" data-action="like" data-font="arial" data-colorscheme="light"></div>
<!-- End WP Socializer Plugin - Facebook Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Retweet Button -->
<a href="http://twitter.com/share" class="twitter-share-button" data-count="vertical"  data-lang="en"  data-url="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-text="Safely Accessing Host Data from the Web - "></a>
<!-- End WP Socializer Plugin - Retweet Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - +1 Button -->
<g:plusone size="tall" href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" ></g:plusone>
<!-- End WP Socializer Plugin - +1 Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - StumbleUpon Button -->
<su:badge layout="5"></su:badge>
<!-- End WP Socializer Plugin - StumbleUpon Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Reddit Button -->
<script type="text/javascript">reddit_url = "http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/";reddit_title = "Safely Accessing Host Data from the Web";reddit_newwindow="1";</script><script type="text/javascript" src="http://www.reddit.com/static/button/button2.js"></script>
<!-- End WP Socializer Plugin - Reddit Button -->
</span>
	<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - LinkedIn Button -->
<script type="IN/Share" data-url="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/" data-counter="top"></script>
<!-- End WP Socializer Plugin - LinkedIn Button -->
</span>
<span class="wpsr-btn">
<!-- Start WP Socializer Plugin - Pinterest Button -->
<a href="http://pinterest.com/pin/create/button/?url=http%3A%2F%2Fwww.attachmate.com%2Fblogs%2Fdatainmotion%2Findex.php%2Fsafely-accessing-host-data-from-the-web%2F&amp;media=http%3A%2F%2Fwww.attachmate.com%2Fblogs%2Fdatainmotion%2Fwp-content%2Fuploads%2F2011%2F09%2FXSS.jpg" class="pin-it-button" count-layout="vertical"><img border="0" src="//assets.pinterest.com/images/PinExt.png" alt="Pinterest" title="Pin It" /></a>
<!-- End WP Socializer Plugin - Pinterest Button -->
</span>
</div><p>The post <a href="http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/">Safely Accessing Host Data from the Web</a> appeared first on <a href="http://www.attachmate.com/blogs/datainmotion">Data In Motion - a Managed File Transfer blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.attachmate.com/blogs/datainmotion/index.php/safely-accessing-host-data-from-the-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>