Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AllowKey=system.run[*] risks? #4

Open
Rockvolleyball opened this issue Jun 21, 2022 · 0 comments
Open

AllowKey=system.run[*] risks? #4

Rockvolleyball opened this issue Jun 21, 2022 · 0 comments

Comments

@Rockvolleyball
Copy link

If I am correct, but not 100% sure, the system.run[*] at this agent config allows the Zabbix server to execute whatever script it wants. Last year I heard about some major security issues with software like Kaseya which allowed the server to install/run elevated commands on workstations.

The system[*] gives me the same feeling, will it allow the Zabbix to do whatever it wants and what if somebody is able to hack my suppliers Zabbix server?

Wouldn't it be much better to restrict the AllowKey to only allow it to run the specific PowerShell script?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant