19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Threats Catalogue Deliberate Acts Remarks<br />

____________________________________________________________________ .........................................<br />

T 2.15 Loss of confidentiality of sensitive data in the<br />

UNIX system<br />

By means of various UNIX programmes it is possible to read/extract userrelated<br />

data held in the <strong>IT</strong> system. This also covers data which can furnish<br />

information on the user performance profile. <strong>The</strong>refore, attention must be paid<br />

both to privacy protection aspects and to the risk that such information may<br />

facilitate abuse.<br />

Example:<br />

With a simple program which, at certain intervals analyses the information<br />

provided by the who command, any user can extract a precise utilisation<br />

profile for an account. In this way it is possible, for instance, to establish the<br />

periods of absence of the system administrator(s) in order to exploit these<br />

absences for illicit acts. Also, it can be established which terminals are<br />

approved for privileged access.<br />

Other programs with similar abuse possibilities are finger or ruser.<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!