Groups | Blog | Home
all groups > iis security > september 2003 >

iis security : Please read


Michael
9/21/2003 7:43:38 PM
All,

This may seem inappropriate but my butt is on the line, so
please read on.

I have 2 developers who have domain admin rights in a
windows 2000 environment. I discovered on Friday that
these 2 have been creating a VPN tunnel to another
companies network and having several machines on that
network interact with one of our machines on the internal
network.

I escalated this issue to our collective supervisor. I
know what his response was and I also know what mine was.

I can guarantee that there is going to be a big turf war
over this one and so I seek your oppinions.

Does this have the potential to become a large security
issue?

Keith W. McCammon
9/22/2003 9:12:42 AM
First of all, you're in the wrong NG.

Regarding your question: What does your security policy state? Should be
pretty clear-cut.

[quoted text, click to view]

Paul Lynch
9/22/2003 10:16:03 AM
Michael,

They are developers. They have Domain Admin rights. The security
implications of those two statements don't get any worse in my
opinion.

Why is your company allowing code monkeys full admin rights to your
systems ? If they're anything like the blaggers I've known in the
past then everything they 'write' (read - steal from somewhere on the
net) will be configured to run in the context of an Admin account (i.e
MOST privilege) and when their 'code' fails to run in a production
environment they'll try to blame your server builds.....

OK, rant over.......

Get escalating asap...


Regards,

Paul Lynch
Bernard
9/22/2003 2:19:10 PM
If the developers are exchanging p&c sensitive data,
of coz this is a big issue ! why don't you investigate
what they have been doing and transferring... or
escalate it to higher authority in your company.

--
Regards,
Bernard Cheah
http://support.microsoft.com/
Please respond to newsgroups only ...



[quoted text, click to view]

AddThis Social Bookmark Button