fencepost
Well-Known Member
- Reaction score
- 2,314
- Location
- Schaumburg, IL
Quick summary since I closed my tabs for it:
Huntresslabs confirmed then announced (after 90 days) that it's possible for anyone who can download an agent from your N-Central server download the agent/probe configuration file which may contain domain admin credentials for your clients in plain text.
To clear the credentials you can either go into each client & location, then Administration, Defaults, Agent & Probe Settings, Credentials tab and clear/change values there (while noting which ones have them or don't), or you can do the bulk setting and go to the same place in your SO (top level), set junk and check the Propagate box which will push it down to everything.
Propagating just the password might be the simplest thing to do if you have thousands of endpoints and hundreds of clients/locations (looking at you @YeOldeStonecat ), though I haven't tested it.
My approach was to turn on the firewall rules I put in place back during the Apache Struts thing so only client sites with static IPs are able to reach our N-Central server, then go through and clear the 5 clients that actually had credentials set.
Edit to call out folks who've talked about Solarwinds, just in case: @TAPtech @Slaters Kustum Machines @Frick @HCHTech (but I think you're on RMM) @nextechinc @freedomit @marley1 @Rosco
Huntresslabs confirmed then announced (after 90 days) that it's possible for anyone who can download an agent from your N-Central server download the agent/probe configuration file which may contain domain admin credentials for your clients in plain text.
To clear the credentials you can either go into each client & location, then Administration, Defaults, Agent & Probe Settings, Credentials tab and clear/change values there (while noting which ones have them or don't), or you can do the bulk setting and go to the same place in your SO (top level), set junk and check the Propagate box which will push it down to everything.
Propagating just the password might be the simplest thing to do if you have thousands of endpoints and hundreds of clients/locations (looking at you @YeOldeStonecat ), though I haven't tested it.
My approach was to turn on the firewall rules I put in place back during the Apache Struts thing so only client sites with static IPs are able to reach our N-Central server, then go through and clear the 5 clients that actually had credentials set.
Edit to call out folks who've talked about Solarwinds, just in case: @TAPtech @Slaters Kustum Machines @Frick @HCHTech (but I think you're on RMM) @nextechinc @freedomit @marley1 @Rosco
Last edited: