Slashdot Mirror


User: lrollins

lrollins's activity in the archive.

Stories
0
Comments
2
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 2

  1. Re:Any idea what part was cr/hacked? on Caveat Emptor: Egghead.com Credit Records Nabbed · · Score: 1

    No I don't work for Egghead in Vancouver. I've had a couple of people that are either employeed or contract over there apply for openings we've had. I've worked on 3k's since the mid 80's, great machines. I also looked at ecometry very briefly, it just doesn't fit our business well.

    Part of the reason I believe it's a hole in the firewall is that I control the one in our office. I run it in paranoid mode. Some people in the office don't like it. If there are legitimate business reasons I will open things up, it's just not going to be a free for all.

  2. Any idea what part was cr/hacked? on Caveat Emptor: Egghead.com Credit Records Nabbed · · Score: 2

    The backend of the system is MACS or what's now called ecometry from Smith-Gardner. The main part of the system runs on an HP3000. Since until recently there wasn't a secure web server on the 3k they used NT/IIS to front end the system on the web.

    So was it actual access to the 3k?
    A problem with NT/IIS?
    A weakness in the S-G software?
    Bad home grown code on eggheads side?
    Poor security practices?

    The later is my guess... it would be rather hard to get to the 3k if it was firewalled properly.

    By the way the Smith-Gardner software is fairly widely used... if you don't believe me take a look at http://www.ecometry.com/clients/cl_list.htm