BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

What Hackers Don’t Want You To Know About User Privileges

Posted March 9, 2011    Peter McCalister

Believe it or there are people out there that aspire to be hackers.  Not just the run of the mill, crack a password or two, but a bona fide Neo who can play with your secure data like a personal version of the matrix.

These would be data pirates and malcontents have websites that teach them their craft and even annual conferences like DEFCON to compare tips, tricks and vulnerabilities.  They are more organized than the average business executive or auditor realizes and they are inspired by nothing short of total access to any and everything on the information super highway, especially what is hidden within your  servers and on any one of your user’s desktops.

The recurring theme and core principal is basically to find access to admin credentials and you own the keys to the kingdom.  So, when users are granted excessive privileges (admin on desktops, root on servers) then you have an environment just begging for a hacker to attack.

Patient to Doctor: Doctor, doctor, when I do this it hurts

Doctor to Patient: Then don’t do it!

Sage advice that hackers don’t want you to know: if you don’t grant admin rights, you don’t run the risk of someone stealing them, hijacking them or even intentionally misusing them from inside.

Leave a Reply

Additional articles

powerbroker-for-mac-diagram-small

PowerBroker for Mac: A Least-Privileged Apple a Day…

Posted July 27, 2015    Jason Silva

BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

Tags:
, ,
PrivilegedAccountManagement

On Demand Webinar – Now is the time for Privileged Account Management

Posted July 24, 2015    BeyondTrust Software

In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

Tags:
, ,
dave-shackleford-headshot

Privileged Account Management: The Time is Now

Posted July 22, 2015    Dave Shackleford

There’s plenty of problems we don’t have great options for in InfoSec today. Malware is a pain point that keeps evolving rapidly. 0-day exploits are tough to prepare for. Privileged account management? We got this. We know the root causes, we know how it manifests, we know how to get it under control effectively, and there are great technology solutions that are enterprise-class.

Tags:
, ,