Quantcast
Channel: Symantec Connect - Security
Viewing all articles
Browse latest Browse all 11462

Issue with SEMS File Share encryption

$
0
0
Non, je n'ai pas besoin d'une solution (je partage des informations seulement)

I've been playing around with SEMS fileshare encryption over the past few days.  The USP for this product is that it protects important files from inside abuse by encrypting the contents whilst its at rest.  At least this is how its been sold in the past.  So even admins of the file shares themselves won't be able to view the encrypted data (HR files, intellectual property are prime examples)

So I have created a centrally controlled encrypted file share environment on our test environment with a 3.3.2 SEMS managing it.  My endpoint is 10.3.2.

I created a fileshare called 2014Test on one of our file servers, and forced encryption of all files and folders inside it. 

So i create a text file on my endpoint, and paste it into the fileshare, and all works as normal:

9c8fed81384cd9d09c32719021ddde24.png

I then log onto the fileserver posing as an admin who wants to read the secret files and load up the same share:

42cec6b100c4504d14fe34eaea1a746b.png

When I try and load up encryptiontext.txt I get this:

c1706f87bf69a524d025029a346e642f.png

When I load up the other file, PGPFS.INI, I get this:

ef89297b9692bad33761c53e90671ca7.png

This is all great, the contents are encrypted and is all complete garbage.  What I do next is DELETE the PGPFS.INI file.  I then upload another file into the fileshare from my workstation:

a64c72ac5b6ed816029159c6344c467e.png

Then, I try and open up the newly input file from my "insider abuse" admin perspective and I get this:

f84fe9600a24f71b1dc15635fe87b33b.png

e9e27220978e03e3aa2027439c468daf.png

 

 

So from the simple act of getting access to the fileshare, I can bypass the encryption in a matter of seconds.  From any sort of compliance perspective this doesn't bode well.  What sort of measures can be put in place to stop this from even happening?  I can't believe the deletion of a system file thats within the share itself is enough to render the entire share completely open.


Viewing all articles
Browse latest Browse all 11462

Trending Articles