Jump to content

Recommended Posts

Posted

A pupil handed a very important and sensitive password to me today that they'd found in a ImperoClientSVC memory dump file on one of our student PCs. All the PCs seem to have a handful of memory dumps.

 

The file is in a location that is set to readable for all authenticated accounts by default (buried in programdata/Impero).

 

Not sure whether to be concerned or impressed with the student.

 

Edit: The password is the proxy password that's set on the Impero server software.

  • Thanks 2
Posted
Any memory dump is crazy sensitive, should never be in a public location, that's how MS got hacked, if they knew what they were doing they could probably find the security key used to communicate with Impero Server, that Impero only added the last time they were hacked
  • 2 months later...
Posted

 

Not sure whether to be concerned or impressed with the student.

 

 

I would be impressed. The student has talent and appears that they haven’t abused it. They did the right thing and brought it to your attention. This will ultimately benefit many schools across the country (hopefully they fix it!). I believe they should be rewarded.

  • Thanks 1
Posted (edited)
You can of course use Impero to block (or monitor) access to system dumps and "other places they have no need to poke about" over and above Group Policy settings. Edited by sigma

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...