Solved

vsphere compliance checker - prevent spying

Posted on 2012-04-13
9
564 Views
Last Modified: 2012-04-13
In relation to the vSphere compliance checker, the check around preventing other users from spying on admin consoles. Can you give a management friendly overview on who and how a user could spy on the consoles (which “consoles” are they referring to), and how this configuration prevents this. What is the risk if a user can see the admin console, what does this give them? If a hacker wants to spy on such consoles, what position must they be in to spy?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 121

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 37841757
When you use the vSphere Client to connect to the ESX/ESXi server, there is an option to Open a Console to a Virtual Server, so you can see the console screen, MULTIPLE consoles can be opened.

This is what is meany by spying!

It's a bit like a Multiple Shadow session, or LogMeIn, Teamviewer, WebEx, etc
0
 
LVL 3

Author Comment

by:pma111
ID: 37841763
So you''d need access to vcenter anyway, and youd be spying on another admin?
0
 
LVL 121
ID: 37841773
Correct.
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 
LVL 3

Author Comment

by:pma111
ID: 37841783
Sorry but whats the definition of console? And by spying on a console, what kind of information could they gather? If they are only admins allowed to access vcenter, is it really much of an issue if they spy on each other, as theyll likely have access to everything anyway!
0
 
LVL 3

Author Comment

by:pma111
ID: 37841785
It sounds like its similar to me spying on my collegue reading a confidential word document, when I could just open the word document myself. Why the need to spy?
0
 
LVL 121
ID: 37841807
If they do not have access to the vSphere Client, they cannot spy. If you prevent access to the vSphere Client, the majority of your risks, are mitigated. So the less Administrators that have access to vSphere Client the better.
0
 
LVL 121
ID: 37841809
Console, is the Remote Connection to the Server, you can view the contents, just like if you are sitting in front of a screen, and someone looks over your shoulder, they can read and see what you are doing.
0
 
LVL 3

Author Comment

by:pma111
ID: 37841831
Have you concerns around your admins spying on one another? Is that why you implement this configuration?
0
 
LVL 121
ID: 37841841
With all Administrators in IT, there must be an element of trust.

also when using Open Console Feature, it states if another console has been opened, but you do not know who.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The following article is comprised of the pearls we have garnered deploying virtualization solutions since Virtual Server 2005 and subsequent 2008 RTM+ Hyper-V in standalone and clustered environments.
When rebooting a vCenters 6.0 and try to connect using vSphere Client we get this issue "Invalid URL: The hostname could not parsed." When we get this error we need to do some changes in the vCenter advanced settings to fix the issue.
Teach the user how to rename, unmount, delete and upgrade VMFS datastores. Open vSphere Web Client: Rename VMFS and NFS datastores: Upgrade VMFS-3 volume to VMFS-5: Unmount VMFS datastore: Delete a VMFS datastore:
Teach the user how to install and configure the vCenter Orchestrator virtual appliance Open vSphere Web Client: Deploy vCenter Orchestrator virtual appliance OVA file: Verify vCenter Orchestrator virtual appliance boots successfully: Connect to the …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question