Skip to content

References

  • PCI DSS v4.0 Standard — Full standard document library
  • Requirement 6.4.3 — Manage all payment page scripts: maintain inventory, provide written authorization and justification, verify integrity
  • Requirement 11.6.1 — Deploy tamper-detection mechanisms on payment pages to alert on unauthorized modifications to HTTP headers and page content
  • OWASP Top 10 Client-Side Security Risks — Candidate risks for browser-side applications and third-party JavaScript
  • Sansec Magecart Research — Magecart groups and digital-skimming campaigns
  • British Airways breach (2018) — Magecart Group 6 injected a skimmer into the BA payment page, compromising 380,000 transactions
  • Ticketmaster breach (2018) — Supply chain attack via compromised Inbenta chatbot script that skimmed payment card data

The AWS offering is Juice Shop only behind an ALB with private Fargate tasks. It is not equivalent to the Azure nine-application full-origin VM offering.