I used to subcontract to someone who did pci compliance tests. One time a bunch of issues came up and we worked to patch them. As we patched things and modified configs the issues went away one by one until only one remained.

Supposedly the remaining issue should have been covered by a software upgrade we did, but it persisted. My boss had to go do other things and left me to investigate. I downloaded the exploit reference code and ran it against the server...nothing. I mucked around with the code and still nothing.

After hours and hours of trying to get the exploit to work my boss called me. Turned out he hadn't quite scrolled to the end of the pci scan list and was looking at the second last report in the list, the one right before the service in question had been upgraded.

