Wondering if anyone can help. I have multiple domains and have run PCI Scans with a trusted vendor for a while now with no issue on our domains. A few days ago on only one of the domains we have, when running a scan, it fails with the error being that the Allaire spectra software is open on the port 443 and proceeds to give me the path that is open.
I do not see anything in Cloudflare’s documentation saying they use that software. It just asks to do the below:
SOLUTION:
Remove the /allaire/spectra/system/admin/ directory from all Spectra servers. This directory is not necessary and was only used in Beta Version
1.0.1.
Our server company says this is a cloudflare issue as we are behind cloudflare.
Is your Origin actually Incapsula? They are saying unsuccessful, but returning a 200. Your PCI Scanner is seeing a 200 and that says the directory exists. It’s a false positive (probably).
When we turned of the SiteLock service, we left the DNS records pointing to them instead of our server company. The day Cloudflare was enabled, the DNS records were changed to cloudflare.
I gave the DNS 1 day to propagate before running the PCI Scan. It seems like that was not enough time as on cloudflare, it was still pointing to the sitelock IP for some reason. I fixed it to point it to our webs server directly and ran the scan again and it seemed to resolve the issue! Well for now anyways! Thank you for all your help!