with admin privileges gone you don't own the machine any more and the risk analysis could say this: should the malicious insider choose to do so, he could fabricate an intricate ring of nazi child pronographers out of the company board/management and have them all locked up for a long time.
thats how f**ked you'd be. so, please, take security seriously.
Main Topics
Browse All Topics





by: TolomirPosted on 2009-09-09 at 06:56:24ID: 25291318
with admin privileges he has full control over the oracle server
execute "sqlplus / as sysdba" on the command shell allows anything on the oracle DB (no need to know the oracle password)
---
The IIS server can also be managed by the administrator, allowing all kind of manipulation from spam provider to trojan distributor, you name it.
---
Tolomir