Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

STAS Security Advice

Hello,

I'am new to this community and just tryin to get STAS running with our 2012 R2 DC.

I followed the "Quick Start Guide" and read many articles about STAS in this Forum but im stucked at the point where all troubleshooting tests are successfull but no live users showing up. I know that there is already another article for that kind of problem.

 

I opened this new one because of this (maybe) interesting information:

As many other admins here I was only able to get the STAS service running without failure by configuring it using an administrative domain account as service user. I do understand that this is necessary because the service has to query remote wmi information and security event log.

What I do not understand is, why the password of the configured account is stored unencrypted in 'stas.ini' file. It's stored as decimal coded MBCS string. With an ASCII table in your hands you dont even need a pocket calculator to read it.

 

I give all admins the advice to limit the access to the STAS program directory exclusivly to administrator accounts otherwise the password is readable to all domain users which have access to this directory.



This thread was automatically locked due to age.
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?