BLACK HAT - Management apps could pose security risk

03.08.2006

In their Black Hat presentation, Goldsmith and Ptacek discussed 12 different methods by which enterprise management systems could be vulnerable to compromise.

In one scenario, a malicious hacker who has gained access to an enterprise network compromises a machine running agent software used by an enterprise management product, then connects through the agent to a central management console that can be used to control agents across the enterprise network.

"At that point, it's pretty much 'game over'," Ptacek said.

There is no evidence that hacking groups are targeting enterprise management applications, but with more research into security vulnerabilities on enterprise platforms, IT managers should be aware of their exposure and take simple steps to make their deployments more secure, the researchers said.

Antivirus and enterprise management applications have been getting more attention in recent months from security researchers who look for product vulnerabilities.