Credit card check
Using the command line to configure the credit card check
-
set appfw profile <name> -creditCardAction ( ([block][learn] [log][stats]) | [none]) -
set appfw profile <name> -creditCard (VISA | MASTERCARD | DISCOVER | AMEX | JCB | DINERSCLUB) -
set appfw profile <name> -creditCardMaxAllowed <integer> -
set appfw profile <name> -creditCardXOut ([ON] | [OFF])<name> -doSecureCreditCardLogging ([ON] | [OFF]) -
To configure a Credit Card relaxation rule by using the command lineUse the bind command to bind the credit card number to the profile. To remove a credit card number from a profile, use the unbind command, with the same arguments that you used for the bind command. You can use the show command to display the credit card numbers bound to a profile.
-
To bind a credit card number a profile
bind appfw profile <profile-name> -creditCardNumber <any number/regex> “<url>”Example: bind appfw profile test_profile -creditCardNumber 378282246310005http://www.example.com/credit_card_test.html-
To unbind a credit card number from a profile
unbind appfw profile <profile-name> -creditCardNumber <credit card number / regex> <url> -
To show the list of credit card numbers bound to a profile.
show appfw profile <profile>
-
Using the GUI to configure the credit card check
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Security Checks.The security check table displays the currently configured action settings for all the security checks. You have 2 options for configuration:
-
If you just want to enable or disable Block, Log, Stats, and Learn actions for Credit Card, you can select or clear check boxes in the table, click OK, and then click Save and Close to close the Security Check pane.
-
If you want to configure additional options for this security check, double click Credit Card, or select the row and click Action Settings to display additional options as follows:
-
Out—Mask any credit card number detected in a response by replacing each digit, except the digits in the final group, with the letter “X.
-
Maximum credit cards allowed per page—Specify the number of credit cards that can be forwarded to the client without triggering a block action.
-
Protected Credit Cards. Select or clear a check box to enable or disable protection for each type of credit card.
-
You can also edit the Block, Log, Stats and Learn actions in the Credit Card Settings pane.After making any of the above changes, click OK to save the changes and return to the Security Checks table. You can proceed to configure other security checks if needed. Click OK to save all the changes you have made in the Security Checks section and then click Save and Close to close the Security Check pane.
-
-
-
In the Advanced Settings pane, click Profile settings. To enable or disable secure logging of credit card Numbers, select or clear the Secure Credit Card Logging check box. (By default, it is selected).Click OK to save the changes.
-
To configure a Credit Card relaxation rule by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules. The Relaxation Rules table has a Credit Card entry. You can double click, or select this row and click Edit to access the Credit Card Relaxation Rules dialogue. You can perform Add, Edit, Delete, Enable, or Disable operations for relaxation rules.
-
Using the learn feature with the credit card check
-
To view or use learned data by using the command line interface
show appfw learningdata <profilename> creditCardNumberrm appfw learningdata <profilename> -creditcardNumber <credit card number> "<url>"export appfw learningdata <profilename> creditCardNumber -
To view or use learned data by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Learned Rules. You can select the Credit Card entry in the Learned Rules table and double-click it to access the learned rules. You can deploy the learned rules or edit a rule before deploying it as a relaxation rule. To discard a rule, you can select it and click the Skip button. You can edit only one rule at a time, but you can select multiple rules to deploy or skip.
You also have the option to show a summarized view of the learned relaxations by selecting the Credit Card entry in the Learned Rules table and clicking Visualizer to get a consolidated view of all the learned violations. The visualizer makes it very easy to manage the learned rules. It presents a comprehensive view of the data on one screen and facilitates taking action on a group of rules with one click. The biggest advantage of the visualizer is that it recommends regular expressions to consolidate multiple rules. You can select a subset of these rules, based on the delimiter and Action URL. You can display 25, 50, or 75 rules in the visualizer, by selecting the number from a drop-down list. The visualizer for learned rules offers the option to edit the rules and deploy them as relaxations. Or you can skip the rules to ignore them. -
Using the log feature with the credit card check
-
Response was blocked or not blocked.
-
Credit card numbers were transformed (X’d out). A separate log message is generated for each transformed credit card number, so multiple log messages might be generated during processing of a single response.
-
Response contained the maximum number of potential credit card numbers.
-
Credit card numbers and their corresponding types.
-
To access the log messages by using the command line.
-
Switch to the shell prompt by running the following command:
Shell-
Tail the
ns.logsin the/var/log/folder to access the log messages pertaining to the Credit Card violations by using the following command:
tail -f /var/log/ns.log | grep SAFECOMMERCE -
-
To access the log messages by using the GUI
-
The GUI includes a very useful tool (Syslog Viewer) for analyzing the log messages. You have a couple of options for accessing the Syslog Viewer: Navigate to the target profile > Security Checks. Highlight the Credit Card row and click Logs. When you access the logs directly from the Credit Card security check of the profile, it filters out the log messages and displays only the logs pertaining to these security check violations.
-
You can also access the Syslog Viewer by navigating to NetScaler® > System > Auditing. In the Audit Messages section, click the Syslog messages link to display the Syslog Viewer, which displays all log messages, including other security check violation logs. This is useful for debugging when multiple security check violations might be triggered during request processing.The HTML based Syslog Viewer provides various filter options for selecting only the log messages that are of interest to you. To access Credit Card security check violation log messages, filter by selecting APPFW in the dropdown options for Module. The Event Type displays a rich set of options to further refine your selection. For example, if you select the APPFW_SAFECOMMERCE and APPFW_SAFECOMMERCE_XFORM check boxes and click the Apply button, only log messages pertaining to the Credit Card security check violations appear in the Syslog Viewer.If you place the cursor in the row for a specific log message, multiple options, such as Module and EventType, appear below the log message. You can select any of these options to highlight the corresponding information in the logs.
-
May 29 01:26:31 <local0.info> 10.217.31.98 05/29/2015:01:26:31 GMT ns 0-PPE-0 :
default APPFW APPFW_SAFECOMMERCE 2181 0 : 10.217.253.62 1098-PPE0
4erNfkaHy0IeGP+nv2S9Rsdu77I0000 pr_ffc http://aaron.stratum8.net/FFC/CreditCardMind.html
Maximum number of potential credit card numbers seen <not blocked>
May 28 23:42:48 <local0.info> 10.217.31.98
CEF:0|Citrix|NetScaler|NS11.0|APPFW|APPFW_SAFECOMMERCE_XFORM|6|src=10.217.253.62
spt=25314 method=GET request=http://aaron.stratum8.net/FFC/CreditCardMind.html
msg=Transformed (xout) potential credit card numbers seen in server response
cn1=66 cn2=1095 cs1=pr_ffc cs2=PPE2 cs3=xzE7M0g9bovAtG/zLCrLd2zkVl80002
cs4=ALERT cs5=2015 act=transformed
May 28 23:42:48 <local0.info> 10.217.31.98
CEF:0|Citrix|NetScaler|NS11.0|APPFW|APPFW_SAFECOMMERCE|6|src=10.217.253.62
spt=25314 method=GET request=http://aaron.stratum8.net/FFC/CreditCardMind.html
msg=Credit Card number 4505050504030302 of type Visa is seen in response cn1=68
cn2=1095 cs1=pr_ffc cs2=PPE2 cs3=xzE7M0g9bovAtG/zLCrLd2zkVl80002 cs4=ALERT cs5=2015
act=blocked
Statistics for the credit card violations
-
To display Credit Card statistics by using command lineAt the command prompt, type:
sh appfw statsTo display stats for a specific profile, use the following command:stat appfw profile <profile name>To display Credit Card statistics by using GUI-
Navigate to System > Security > Web App Firewall.
-
In the right pane, access the Statistics Link.
-
Use the scroll bar to view the statistics about Credit Card violations and logs. The statistics table provides real-time data and is updated every 7 seconds.
-
Highlights
-
The Web App Firewall enables you to protect credit card information and detect any attempts to access this sensitive data.
-
To use the Credit Card protection check, you must specify at least one type of credit card and an action. The check is then applied to HTML, XML, and Web 2.0 profiles.
-
You can pipe the output of
sh appfw profilecommand and grep for CreditCard to see all the Credit Card specific configuration.For example,sh appfw profile my_profile | grep CreditCarddisplays the configured settings of various parameters and the relaxation rules for the Credit Card check in the Web App Firewall profile namedmy_profile. -
You can exclude specific numbers from Credit Card inspection without bypassing the security check inspection for the rest of the credit card numbers.
-
Relaxation is available for all Web App Firewall protected credit card patterns. In the GUI, you can use the visualizer to specify Add, Edit, Delete, Enable, or Disable operations on relaxation rules.
-
The Web App Firewall learning engine can monitor the outgoing traffic to recommend rules based on observed violations. Visualizer support is also available for managing the learned credit card rules in the GUI. You can edit and deploy the learned rules, or skip them after careful inspection.
-
The setting for number of allowed credit cards applies to each response. It does not pertain to the cumulative total of credit card numbers observed during the entire user session.
-
The number of X’d out digits depends on the length of the credit card numbers. Ten digits are X’d out for credit cards that have 13 through 15 digits. Twelve digits are X’d out for credit cards that have 16 digits. If your application does not require sending the entire credit card number in the response, Citrix® recommends that you enable this action to mask the digits in the credit card numbers.
-
The X-out operation transforms all the credit cards and works independently of the configured settings for the maximum number of allowed credit cards. For example, if there are 4 credit cards in the response and the creditCardMaxAllowed parameter is set to 10, all 4 credit cards are X’d-out, but they are not blocked. If the credit card numbers are spread out in the document, a partial response with X’d-out numbers might be sent to the client before the response is blocked.
-
Do not disable the doSecureCreditCardLogging parameter before due consideration. When this parameter is turned off, the credit card numbers are displayed and are accessible in the log messages. These numbers are not masked in the logs, even if the X-out action is enabled. If you are sending logs to a remote syslog server, and the logs are compromised, the credit card numbers can be exposed.
-
When the response page is blocked because of a Credit Card violation, the Web App Firewall does not redirect to the error page.