ColonelPanic Posted November 13, 2023 Posted November 13, 2023 A pupil handed a very important and sensitive password to me today that they'd found in a ImperoClientSVC memory dump file on one of our student PCs. All the PCs seem to have a handful of memory dumps. The file is in a location that is set to readable for all authenticated accounts by default (buried in programdata/Impero). Not sure whether to be concerned or impressed with the student. Edit: The password is the proxy password that's set on the Impero server software. 2
OLPTech Posted November 13, 2023 Posted November 13, 2023 Interesting, I have sent this edugeek thread to someone at Impero to see if theres anything that can be done. 1
psydii Posted November 13, 2023 Posted November 13, 2023 All the PCs seem to have a handful of memory dumps. This seems like a case of nominative determinism.
OLPTech Posted November 13, 2023 Posted November 13, 2023 I've just heard from them, they recommend you create a ticket but they couldn't replicate it on the newest version (8.6.22)
mavhc Posted November 14, 2023 Posted November 14, 2023 Any memory dump is crazy sensitive, should never be in a public location, that's how MS got hacked, if they knew what they were doing they could probably find the security key used to communicate with Impero Server, that Impero only added the last time they were hacked
ColonelPanic Posted November 14, 2023 Author Posted November 14, 2023 I've just heard from them, they recommend you create a ticket but they couldn't replicate it on the newest version (8.6.22) Thank you We're running 8.6.22, and it's in a dump as recent as last week. I've emailed [email protected] anyway, see what they say. 1
benward1 Posted February 11, 2024 Posted February 11, 2024 Has any more info been shared on this issue? Slightly concerned it may exist in 8.6.02 which we’re running.
FN-GM Posted February 11, 2024 Posted February 11, 2024 Not sure whether to be concerned or impressed with the student. I would be impressed. The student has talent and appears that they haven’t abused it. They did the right thing and brought it to your attention. This will ultimately benefit many schools across the country (hopefully they fix it!). I believe they should be rewarded. 1
sigma Posted February 11, 2024 Posted February 11, 2024 (edited) You can of course use Impero to block (or monitor) access to system dumps and "other places they have no need to poke about" over and above Group Policy settings. Edited February 11, 2024 by sigma
PotNoodleTech Posted February 13, 2024 Posted February 13, 2024 Hire that pupil to "white hat" keep an eye on your system!
OLPTech Posted February 15, 2024 Posted February 15, 2024 Fixed in the latest version that they've just released (8.6.25) 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now