Select to view content in your preferred language

relevant news - ArcGIS Server as backdoor

65
3
3 hours ago
dsinha
by
Frequent Contributor
0 Kudos
3 Replies
D_Atkins
Regular Contributor

Relevant statement:

"Flax Typhoon leveraged valid credentials – reportedly a portal administrator account – to deploy the malicious extension."

Seems less of a 'backdoor', as the title implies, and more of a compromised admin account.

0 Kudos
George_Thompson
Esri Notable Contributor
ThomasHoman
Frequent Contributor

Whomever the entity was that had their installation compromised violated a very standard rule of modern cyber security hygiene - NEVER, EVER, EVER allow an administrative interface to be exposed to the Internet.

Administrative access needs to be behind a VPN connection or at least a solid Multi Factor Authentication (MFA) setup for login. Both VPN + MFA is the preferred armor to your kingdom for any administrative credentials. 

Tom

0 Kudos