Solved

Firewall -- detecting ex-owner activity ?

Posted on 2016-09-01
1
42 Views
Last Modified: 2016-09-03
I am looking to upgrade my firewall, stay current
with all OS, database, etc patches, and keep lots of backups

What firewall / software / etc do you recommend so I can try to monitor below step #4 ?
------------------------------------------------------------------------------------------------------------------------------------------------------
1. owner installed remote software (i.e. LogMeIn, TeamViewer, etc) onto server and several machines

2. owner quits

3. We disabled CFO’s VPN & Windows account, changing the password of all other VPN users since CFO might have known, uninstalling LogMeIn, TeamViewer, etc from whatever machines we find it on

4. owner might still access via some type of backdoor into the system
0
Comment
Question by:finance_teacher
1 Comment
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 41780952
Logmein, teamviewr initiate outgoing connections, firewall rules on outgoing traffic would be necessary .....

Changing all the passwords internal and external resources is the first thing.
If tge organization had a paid service from logmein, teamviewr, gotomypc, etc. securing those accounts by managing the users who can access it and changing those passwords.

Audit all the installed application. ..
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now