BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

What Hackers Don’t Want You To Know About User Privileges

Posted March 9, 2011    Peter McCalister

Believe it or there are people out there that aspire to be hackers.  Not just the run of the mill, crack a password or two, but a bona fide Neo who can play with your secure data like a personal version of the matrix.

These would be data pirates and malcontents have websites that teach them their craft and even annual conferences like DEFCON to compare tips, tricks and vulnerabilities.  They are more organized than the average business executive or auditor realizes and they are inspired by nothing short of total access to any and everything on the information super highway, especially what is hidden within your  servers and on any one of your user’s desktops.

The recurring theme and core principal is basically to find access to admin credentials and you own the keys to the kingdom.  So, when users are granted excessive privileges (admin on desktops, root on servers) then you have an environment just begging for a hacker to attack.

Patient to Doctor: Doctor, doctor, when I do this it hurts

Doctor to Patient: Then don’t do it!

Sage advice that hackers don’t want you to know: if you don’t grant admin rights, you don’t run the risk of someone stealing them, hijacking them or even intentionally misusing them from inside.

Leave a Reply

Additional articles

gartner market guide image - aug 2014

Introducing the Gartner Market Guide for Privileged Account Management

Posted July 29, 2014    Chris Burd

Gartner recently released a new Market Guide for Privileged Account Management (PAM), and we’d like to share a complimentary copy with you. The report includes PAM market analysis and direction, vendor overviews, and recommendations for selecting PAM solutions for your environment. BeyondTrust is one of two representative vendors (out of 20) to address all solution…

Tags:
, , , , , , , ,
Integrating Least Privilege and Password Management to Solve Account Security Challenges

Integrating Least Privilege and Password Management to Solve Account Security Challenges

Posted July 24, 2014    Morey Haber

There is a reason all BeyondTrust Privileged Account Management (PAM) solutions share the PowerBroker name: They all inherently enable you to reduce user-based risk and can be integrated under a centralized IT risk management platform. Here’s one common use case that demonstrates how this integration changes the playing field. Consider the challenge of privileged access:…

Tags:
, , , , ,
PowerBroker Password Safe Password Age Report

Reshaping Privileged Password Management with Password Safe 5.2

Posted July 21, 2014    Martin Cannard

Today, we’re pleased to unveil the latest edition of our privileged password management solution, PowerBroker Password Safe. I’ll start with a brief intro of what’s new and then tell you a little about the driving factors behind Password Safe development. New features for mitigating password risk and ensuring accountability enterprise-wide Here’s the 10,000-foot overview of…

Tags:
, , ,