BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

sudo authentication bypass when clock is reset

Posted March 7, 2013    Rod Simmons

A recent discovery by a German researcher, Marco Schoepl, found that it is possible for a user to bypass sudo authentication by resetting the clock. To read more about this vulnerability see the articles on seclist.org and threatpost.com. What we have found is that many highly secure customers have already adopted the timestamp_timeout=0 setting which will bypass the default 5 minute password reentry interval and requires authentication for each command.

clock-resetYou could consider this vulnerability a configuration issue but it does highlight a general need to use a solution that provides an option for IO logging. Our PowerBroker Unix & Linux solution is a Command Control solution that also provides a method to perform IO Logging so you can replay a user’s entire session, after all, once they have elevated permissions it becomes vital to securely log the actions of that user.

It is always possible to have a configuration issue in any security system due to flexibility and general complexity of building a secure system. The key principle is to only delegate the rights needed and perform IO logging along with multi-factor authentication as an additional safety measure.

If you require a Sudo replacement, or want to implement greater controls where compliance requires it, PowerBroker Servers can help. Learn more about PowerBroker Servers now!

Tags:
, , , ,

Leave a Reply

Additional articles

dave-shackleford-headshot

Why You Still Suck at Patching…and How to Turn Your Life Around

Posted March 25, 2015    Dave Shackleford

Live webinar | March 26, 2015 | 10am PT/1pm ET | Dave Shackleford, SANS Instructor | Why You Still Suck at Patching…and How to Turn Your Life Around

Tags:
, ,
infographic

Privilege Gone Wild 2: Over 25% of Organizations Have No Privileged Access Controls

Posted March 24, 2015    Scott Lang

BeyondTrust recently conducted a survey, with over 700 respondents, to explore how organizations view the risk of misuse from privileged account misuse, as well as trends in addressing and mitigating those risks.

Tags:
,
webinar_ondemand

On Demand Webinar – A Security Expert’s Guide: The Windows Events You Should be Tracking and Why

Posted March 23, 2015    Lindsay Marsh

On-Demand Webinar – Windows Security Expert and MCSE, Russell Smith, discusses the Windows Events you should be tracking right now and why. He will also show you how to set up Event Log subscriptions so you have better monitoring across your Windows environments.

Tags:
, ,