** Agreed, but I assume that is only completely safe provided that the arcache executable connects through a socket and not through tcp connections... I see I'll have to RTM about it.

thanks for the prompt answer on my query.

/Jonas Stevnsvig

Den 15-11-2011 23:24, Pierson, Shawn skrev:
**

Since someone would have to have to be on the server to execute that command, it should be relatively safe providing that your server itself is secure.

 

Thanks,

 

Shawn Pierson

Remedy Developer | Southern Union

 

From: Action Request System discussion list(ARSList) [mailto:arslist@ARSLIST.ORG] On Behalf Of Jonas Stumph Stevnsvig
Sent: Tuesday, November 15, 2011 3:57 PM
To: arslist@ARSLIST.ORG
Subject: Re: Demo <sigh>

 

**

Now I'm curious - how can you harden the server to prevent this workaround?

Den 15-11-2011 22:47, Kemes, Lisa skrev:

**

Thanks so much!!  I used this and it worked!  <whew!>

Lisa

 

 


From: Action Request System discussion list(ARSList) [mailto:arslist@ARSLIST.ORG] On Behalf Of Nathan Aker
Sent: Tuesday, November 15, 2011 4:38 PM
To: arslist@ARSLIST.ORG
Subject: Re: Demo <sigh>

**

Haven’t tried this procedure in a while, but it should create a new Admin account.  The last parameter sets it up a as an Admin.  Nate.

 

 

 

Go to a command line, and CD to the install directory.  Look for a binary called arcache

 

When you get to it, type the following:

 

arcache -Ua -eTEMP999 -lw 1 -n "TEMPADMIN"-p"" -s <servername> -g "1;"

 

 

Then, log into the server with a login of TEMPADMIN, no password

 

Nathan Aker
ITSM Solution Architect

McAfee, Inc.


 

From: Action Request System discussion list(ARSList) [mailto:arslist@ARSLIST.ORG] On Behalf Of Kemes, Lisa
Sent: Tuesday, November 15, 2011 2:43 PM
To: arslist@ARSLIST.ORG
Subject: Demo <sigh>

 

**

I hope others have done the same thing.

 

Installed AR System Application Software 7.6.04 SP2 on Windows 2008 server (we are using Oracle 11gR2).

 

After install, I logged on using Demo, then went to the User Form and added my account and then changed the Demo Account from Fixed to Read (so I could add 2 other users).

 

Logged out and logged in as myself and DOH! I didn't add administrator permissions on my account so I don't have admin privileges.

 

Logged out and then back in as Demo and I guess when I changed the license from fixed to Read it took out the Admin Privilege?

 

I have some info from the ARSlist archives to use arcache to add a fixed license back to demo, but will it give it the admin priv's back?

 

 

Lisa Kemes

AR System Developer
TEIS - USA

+1 717 810 2408 tel
+1 717 602 9460 mobile
lisa.ke...@te.com
100 Amp Drive

Harrisburg, PA 17112

Description: Image removed by sender.

www.te.com

Description: Image removed by sender.Description: Image removed by sender.Description: Image removed by sender.Description: Image removed by sender.Description: Image removed by sender.

 

_attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_

_attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_ _attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_

 

_attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_

Private and confidential as detailed here. If you cannot access hyperlink, please e-mail sender. _attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_

_attend WWRUG12 www.wwrug.com ARSlist: "Where the Answers Are"_

Reply via email to