Welcome, Guest
Username: Password: Remember me

TOPIC: Security issue PRT file - Macola Programmers please FIX

Security issue PRT file - Macola Programmers please FIX #539

  • bruggles
  • bruggles's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 16
  • Karma: 0
After an internal audit on our information systems it appears that when a user Prints to Screen using Macola Progression 7.6.300, the software is leaving a copy of the information in ASCII format with a .PRT extension.

As we use the Payroll module and this information is one of those things most business's need and want to contain we were aghast that we found Progression leaves a copy of this information in the DATA folder with a .PRT extension. A user only has to open the file in Notepad to view the information. Running a search on the M: drive would also reveal this and possibly other confidential information being left in easy to read ASCII file format.

I would like to requesting Macola Programming staff to please fix this immediatly. PRINT TO SCREEN should be PRINT TO SCREEN not PRINT TO SCREEN AND CREATE FILE in an OPEN folder without telling the currently logged in user. This could not be that hard to fix. I would think the easiest would be to create a function to delete the file once the Print Screen Interface is closed?

Additionally we are now looking at issues with data being left behind from the direct deposit transfer files.

Could someone at Macola please acknowledge this problem is being looked at? TIA
The administrator has disabled public write access.

Security issue PRT file - Macola Programmers please FIX #541

  • bruggles
  • bruggles's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 16
  • Karma: 0
We just discovered our Progression 7.6.3 appears to be spawning 3 ascii .dat files that include bank account numbers employee names and pay information.

The file names are

ACHTAPE.DAT
ACHTRANS.DAT
ACHTAPEL.DAT

Is it ok to delete these files after running a transfer? Will it create new files each time? Or do I risk causing a problem with Macola Payroll?

We would like to keep this information more secure. Could a feature be added to the Payroll Module to delete these files?

thanks
The administrator has disabled public write access.

Security issue PRT file - Macola Programmers please FIX #542

  • dgillz
  • dgillz's Avatar
  • OFFLINE
  • Platinum Boarder
  • Posts: 395
  • Thank you received: 14
  • Karma: 6
I disagree that printing to screen will create these files. Printing to disk however will create these files and all your comments about them are correct.
www.gainfocus.biz
Worldwide support for Macola Progression, Macola ES, Synergy, Event Manager and Crystal Reports.
The administrator has disabled public write access.

Security issue PRT file - Macola Programmers please FIX #549

  • MichaelS
  • MichaelS's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
  • Karma: 0
We have a similar issue with easily accessible PRTs. Has this been reported by anyone to at Macola?

Thanks
The administrator has disabled public write access.
Time to create page: 0.032 seconds
Powered by Kunena Forum  Protected by R Antispam