If a company’s system administrator leaves the company, how can the company ensure that the administrator doesn’t still have any backdoor access to the company’s network, email and systems?
The first one that comes to my mind is to revoke all privileges from the ex-employee’s account (then delete it?)
How about backdoors? How can you detect them and stop 'em from entering your network?
no hard'n fast way to actually do that.. just look into admins group and rename all of them, change pwds, the ones u dunno, try contacting them .. stuff like that..
Well on all your critical servers you need to check all the TASKS scheduled and all the services running. Some of the backdoors are suppose to trigger at a certain time.
But checking specifcally for backdoor is a painstaking job.
Like Faizy said, one need to disable the account immediately. I would say that dont delete the account for some time. Just forthe sake of inventory later wards.
and check all the groups he is member of..
Ill ask our security admin for that , and ill get back to you.
Well what did u expect? You know all the answers, and back doors are exactly that, hidden things.
If you don't know about those back doors (security expert and all) then what will happen to the rest of us mere mortals!!
^ nahee jigar … that’s not the case. I’m a human and born to make mistakes, to forget … so I thought someone bright (like yourself) could enlighten me on the topic …