On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Mar 2, 2005 1:52:00 AM

Service provider PayMaxx shuttered additional parts of its online payroll site this week, after a Web programmer continued to find holes in the system.

PayMaxx's further closure of its Web services comes after a Web programmer, Aaron Greenspan, discovered that the company's initial attempt to block malicious access had fixed some flaws but left others unresolved.

While still referring to the data leak as "limited in scope," the online payroll processor closed down its PayView and Instant W2 services, the company said in a statement. The services will remain down until PayMaxx has completed a thorough security analysis and redesigned the site's architecture.

"We have sent all clients and key partners e-mails alerting them to the situation, and we are contacting the companies we believe may have been potentially affected by the hacking," PayMaxx said in a statement sent to CNET News.com.

The dispute between PayMaxx and Greenspan, president of Web services start-up Think Computer and a former PayMaxx customer, over the security of the company's Web site continued this week. PayMaxx referred to Greenspan as a "hacker," while the Web programmer maintained that the security problem is far worse than divulged by the payroll company.

The data leak comes at a time when several high-profile attacks have Congress looking into further legislation to protect people's private information. In February, data aggregator ChoicePoint warned that almost 150,000 consumer files had been compromised by scam artists who had set up fake companies to garner identity information. Last week, financial services giant Bank of America alerted government workers that backup tapes containing their information had gone missing.

Greenspan said he uncovered the problem with PayMaxx's Web site about three weeks ago and tried to contact the company. He said PayMaxx did not respond, so he posted a report detailing the flaws. That prompted PayMaxx to shut down its Web service for retrieving W2 information. Greenspan continued to prod the site's security and discovered more vulnerabilities this weekend, he said.

Greenspan said his attempts to find flaws in the site have been motivated by protecting his own information, from when Think Computer was a client of PayMaxx. "Think had an obvious interest in seeing that the problem would be resolved properly since its own data was stored in the affected systems," he said in an e-mail interview.

PayMaxx does not agree. The Web programmer has been far too intent on poking holes in the company's systems and has "numerous inaccuracies" in his report, PayMaxx said in a statement. The company did not specify which parts of his report were incorrect.

"We believe the hacker has violated federal law and we will take whatever action is necessary to protect the interests of our clients and our company," the company said.

PayMaxx has contracted an outside security company to test its Web applications' security and has ordered additional hardware and software to better detect intrusions, PayMaxx said in a statement.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 11 Talkback(s)
This looks like a matter of...
Looks to me like Paymaxx is mad at this poor hacker for making it impossible to sweep thier poor security under the carpet.

'Let's sue the slob who tried to help us, and tried to protect our customers!'.

Isn't capitalism wonderful when it works?... (Read the rest)
Posted by: KOS-MOS Posted on: 03/02/05 You are currently: a Guest | | Terms of Use
PayMaxx you should be thanking Greenspan.  IT Scion | 03/01/05
He's following protocol  Roger Ramjet | 03/02/05
It's time to pull the plug on the .net...  BitTwiddler | 03/02/05
Yes, ALL NEW NOMENCLATURE  Roger Ramjet | 03/02/05
Did I miss something?  IT Scion | 03/02/05
You can always tell...  drabicky | 03/02/05
ChoicePoint., BOA and now this  Sunny Jalolly | 03/02/05
The great thing about America  Roger Ramjet | 03/02/05
i agree...  wimbo_z | 03/02/05
Read the "Patriot" Act  Sunny Jalolly | 03/02/05
This looks like a matter of...  KOS-MOS | 03/02/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline